Security & Trust
Enterprise-grade protection for your confidential documents. Built on Microsoft Azure with zero-trust architecture.
How We Securely Process Your Documents
Every step of AI processing happens within Microsoft Azure's secure infrastructure in Canada Central. Your data is encrypted, isolated, and never used for AI training.
Encrypted Upload
Your audio recordings, documents, and photos are transmitted over TLS 1.2+ encryption. Data is never sent in plain text.
Secure Storage
Files are stored in Azure Blob Storage with AES-256 encryption at rest and per-client encryption scopes for data isolation.
AI Processing in Canada
Azure OpenAI transcribes audio (Whisper) and generates reports (GPT-4o-mini) — all within Canada Central. Your data never crosses borders.
Zero Data Retention by AI
Azure OpenAI does NOT store or train on your data. Your prompts and outputs are processed and immediately discarded by Microsoft.
Report Generated
Your completed report is stored encrypted in Azure Blob Storage. Only you can access, download, or share it.
You Stay in Control
Delete any document, recording, or your entire account at any time. Deletion is permanent and verified across all systems.
Data Residency
All data stays in Canada- All Azure resources hosted in Canada Central region
- Database, file storage, and AI models — all in Canada
- Compliant with PIPEDA (Canada) data sovereignty requirements
- Only payment processing (Stripe/PayPal) and OAuth (Google/Microsoft) may transit through the US — disclosed in our Privacy Policy
Network Isolation
Private, air-gapped database- Database runs inside a private Azure Virtual Network (VNet) — no public internet access
- Private DNS Zone ensures database hostname resolves to internal IP only
- Only the application server can reach the database — zero external access
- SSL/TLS required on all database connections
Encryption at Every Layer
Your data is protected by industry-standard encryption whether it's moving, stored, or being processed.
In Transit
TLS 1.2+
All data encrypted between your device, our servers, and Azure services.
At Rest
AES-256
Files, database, and search index encrypted with Azure-managed AES-256 keys.
Secrets
Azure Key Vault
All API keys, passwords, and tokens stored in HSM-backed Key Vault — never in code.
Tenant Isolation
Per-User Scoping
Per-client encryption scopes in storage. Mandatory user filters on all data queries.
Enterprise Cloud Infrastructure
FieldCherry runs entirely on Microsoft Azure — the same cloud platform trusted by 95% of Fortune 500 companies.
Azure App Service
Premium v3 compute with Managed IdentityAzure Key Vault
HSM-backed secret managementAzure OpenAI
GPT-4o-mini, Whisper, EmbeddingsAzure Blob Storage
AES-256 encrypted file storageAzure AI Search
Isolated vector knowledge baseAzure MySQL
VNet-isolated, SSL-requiredAzure Virtual Network
Private network isolationApplication Insights
Real-time monitoring & alertingOur AI Data Commitment
Clear, non-negotiable guarantees about how your data is handled.
We Never Train AI on Your Data
Microsoft's Azure OpenAI Service explicitly guarantees that your prompts, completions, and uploaded data are not used to train, retrain, or improve any AI models. This is a contractual obligation, not just a policy.
Zero Data Retention by AI
When Azure OpenAI processes your audio or documents, the data is used only for that request and immediately discarded. No copies are kept. No logs of your content are stored by the AI service.
Complete Tenant Isolation
Your data is strictly separated from other users at every layer: database queries, file storage encryption scopes, and AI knowledge base search filters are all user-scoped by design.
Right to Erasure — Guaranteed
Delete your account and every trace of your data is permanently removed across 10 verified steps: knowledge base, marketing, invoices, reports, templates, payments, business data, logs, and user records.
Application Security Controls
Defense-in-depth at the application level, following OWASP best practices.
Content Security Policy
Strict CSP headers block XSS and unauthorized resource loadingRate Limiting
100 requests/min global, 5 auth attempts per 15 minStrong Authentication
12-char passwords, JWT tokens, Google & Microsoft OAuthClickjacking Protection
X-Frame-Options + frame-ancestors prevent iframe embeddingServer Info Hidden
Server, X-Powered-By, and ASP.NET headers removedAnti-CSRF Tokens
All state-changing forms protected against cross-site request forgerySecurity FAQ
parent_user_id + client_id filter on every query — there is no code path that bypasses it.
Have Security Questions?
Our business is ready to discuss your security and compliance requirements.
security@fieldcherry.com