Last updated July 20, 2026

Security overview

Enterprise-grade practices for map intelligence and field operations.

Security controls

Encryption

TLS in transit and encrypted storage for sensitive data.

Authentication

Secure sign-in, session management, and MFA support.

RBAC

Role-based access across teams and territories.

Monitoring

Operational and security event monitoring.

Security philosophy

DotlyMaps treats security as a core product requirement, not an afterthought. We apply defense-in-depth across infrastructure, application, and operational layers, and we publish our compliance roadmap transparently.

We design for least privilege, secure defaults, and continuous improvement. Our goal is to earn the trust of procurement teams, IT administrators, and security reviewers through honest, verifiable practices.

Platform security

The DotlyMaps application enforces authentication on protected routes, validates input, and separates customer data by account boundaries. Security patches are prioritized based on risk and deployed through controlled release processes.

Infrastructure security

Production services run on enterprise cloud infrastructure with network segmentation, hardened configurations, and automated patching where applicable. We do not disclose specific cloud providers in public documentation unless configured by your administrator.

Data protection

Customer map data, CRM sync records, and field activity remain under customer ownership. We process data only to deliver the DotlyMaps service and as described in our privacy documentation.

Secure authentication

We support strong password requirements and multi-factor authentication for qualifying accounts. Session tokens are protected and expire according to security policy.

Encryption

All customer traffic uses TLS. Sensitive data at rest is encrypted using industry-standard mechanisms on our cloud infrastructure.

Monitoring and logging

We collect application and infrastructure telemetry to detect availability issues and security-relevant events. Logs are retained per our Data Retention Policy.

Backup strategy

Critical production data is backed up on a regular schedule with tested restore procedures. See our Backup Policy for details.

Incident response

We maintain runbooks for detection, triage, containment, and customer notification. See our Incident Response page for reporting contacts.

Continuous improvement

Our security program evolves through internal reviews, customer feedback, vulnerability reports, and planned third-party assessments. We never display certification badges until officially certified and approved for public display.

Security questions

How is customer data protected?

DotlyMaps protects customer data using defense-in-depth controls including TLS encryption in transit, encryption at rest for sensitive data, role-based access controls, secure authentication, monitoring, and regular backups. See our Trust Center for detailed security documentation.

How is customer data encrypted?

Data is encrypted in transit using TLS. Sensitive data at rest is protected using industry-standard encryption on our cloud infrastructure.

Is data encrypted?

Yes. Data is encrypted in transit using TLS. Sensitive data at rest is protected using industry-standard encryption on our cloud infrastructure.

Who can access customer data?

Access is limited by role-based permissions. Only authorized personnel with a business need can access production systems, and access is reviewed regularly.

Does DotlyMaps support MFA?

Multi-factor authentication (MFA) is supported for administrative and enterprise accounts where configured. Contact your account team or [email protected] for availability on your plan.

Where is data hosted?

DotlyMaps runs on enterprise cloud infrastructure. Contact [email protected] for current region and residency details for your contract.

Where is customer data stored?

DotlyMaps runs on enterprise cloud infrastructure. Contact [email protected] for current hosting regions and data residency options available under your agreement.

Who owns customer data?

Customers retain ownership of the data they upload, sync, or generate in DotlyMaps. We process data only to provide the service and as described in our privacy documentation.

Do you support responsible disclosure?

Yes. Security researchers can report vulnerabilities to [email protected]. We review good-faith reports and work with reporters on remediation.

How often are backups performed?

Critical production data is backed up on a regular automated schedule. Backup frequency and retention details are documented in our Backup Policy and available upon request for enterprise reviews.

How is AI data used?

AI features process customer content to deliver requested functionality. We do not use customer data to train public models. See Responsible AI for details.

How are vulnerabilities handled?

We maintain a vulnerability management process including dependency monitoring, remediation workflows, and a responsible disclosure program. Reports can be submitted to [email protected].

What AI models are used?

DotlyMaps AI features use managed model providers and purpose-built services to deliver requested functionality such as natural-language queries and insights. Model selection is documented internally and available to enterprise customers upon request.

Is customer data used to train AI?

No. Customer data is not used to train public or shared foundation models unless you explicitly enable a feature that requires it and agree to applicable terms. AI features process data only to deliver the functionality you request.

How can customers report security issues?

Report security concerns to [email protected] or through our Vulnerability Disclosure Policy. We review good-faith reports and work with researchers on responsible remediation.

Who can access customer data internally?

Access is limited by role-based permissions and the principle of least privilege. Only authorized personnel with a documented business need may access production systems, and access is reviewed periodically.

How do you handle security incidents?

We follow a structured incident response process covering detection, containment, investigation, customer notification when required, recovery, and post-incident review. See our Incident Response trust page for an overview.

Can we export or delete our data?

Yes. Customers can request data export and deletion in accordance with their agreement and applicable privacy laws. See our Data Retention Policy and Privacy Policy for details.

Do you support SSO or SAML?

Enterprise SSO integrations are available for qualifying plans. Contact your account team for supported identity providers and configuration guidance.

How are API credentials secured?

API keys and secrets are stored using secure configuration management. Customers should rotate credentials periodically and never embed secrets in client-side code.

What compliance programs are you pursuing?

We publish a transparent compliance roadmap showing implemented controls and planned initiatives. We do not display certification badges until officially certified and approved for public display.

Do you conduct penetration testing?

An annual independent penetration testing program is planned as part of our security roadmap. Results inform remediation priorities and control improvements.

How is session security managed?

Sessions use secure cookies and timeout controls. Administrative sessions require strong authentication, and suspicious activity may trigger additional verification or lockout.

What logging and monitoring is in place?

We monitor application and infrastructure telemetry for availability, performance, and security-relevant events. Logs are retained per our Data Retention Policy.

How do you manage third-party vendors?

Subprocessors and vendors undergo security review based on risk. Our Vendor Security Policy describes assessment, contractual requirements, and ongoing monitoring.

Is DotlyMaps GDPR-ready?

We provide privacy documentation including a Data Processing Addendum template for B2B customers. Legal compliance depends on your use case, configuration, and executed agreements, consult qualified counsel.

How is AI output validated?

AI-assisted outputs are designed for human review before business decisions. Teams should validate AI-generated insights against source data and established workflows.

What is your uptime target?

We target high availability for core services and publish status updates through our public status page. Enterprise customers can request SLA details during procurement.

How are passwords stored?

Passwords are hashed using industry-standard algorithms. We enforce minimum complexity requirements and encourage multi-factor authentication and password managers.

Can we get a security questionnaire completed?

Yes. Enterprise customers and procurement teams can contact [email protected] with standard security questionnaires. We provide Trust Center documentation to support reviews.