Security & data
Who sees what, and what gets recorded. As it works today.
How access, sign-in, record keeping and offline copies work in DatumPro now. What is not in place yet is listed at the end.
Who can see what
- A role, given at a scope
- Access is a role given to a person or a team at a scope, such as a client or a project, or across the whole organisation. The role applies there and to everything beneath it.
- Checked by the server
- Before the server returns or changes a client, project, job, map feature, catalogue or export, it checks the person’s role. The screen never decides on its own.
- A job share is bounded by the job’s area
- Share one job and the person reaches map features only inside that job’s area. The project’s layers and catalogue come with the share, so they have what they need to work.
- Read-only viewers
- By default, the Viewer role opens a shared map with no permission to change anything. Viewers sign in like everyone else: there is no public link to a map.
- Crews change their own work
- By default, a field crew member reads every feature their share reaches and adds new ones, but changes or deletes only the features they added.
- You can only share what you hold
- To give someone a role at a scope, you must already hold every permission in it there, so sharing cannot pass on more access than you have.
Signing in
- Keycloak holds the accounts
- Sign-in runs through Keycloak, which keeps user accounts and sign-in credentials in a database of its own, separate from project data.
- Your company sign-in, if you want it
- Keycloak can connect to your company’s identity provider, so people sign in with the account they already have. Nothing is connected by default.
What is recorded
- An append-only audit trail
- By default, creating, changing or deleting a client, project, job, catalogue or map feature is recorded: who did it, when, and what changed. Entries are only ever added; none is edited in place.
- Where each map edit was made
- Every map edit records the position of the device that made it, and how accurate that position was. That position is kept in the audit record, not shown in the feature’s details. The map does not accept an edit from a device that cannot give its position.
- Edits are timed by the server
- The time of an edit comes from the server’s clock, not the tablet’s, so an edit made offline is timed when it reaches the server.
- Where people are on the map
- By default, while the map is open, the device also reports its position to the server every 30 seconds. Anyone who can open the project sees where colleagues were last seen in the past 12 hours and the route each took today; someone who manages the project can look back up to 30 days.
Working offline
The map keeps working without signal because the work is stored on the device.
- Edits wait on the device
- Edits are saved in the browser’s storage on the tablet or laptop first, then sent to the server when there is a connection. Projects opened on the device are kept there for offline use.
- Not encrypted by DatumPro
- DatumPro does not add its own encryption to that stored copy. Protect field devices with the device’s own encryption and a screen lock.
- A new person starts clean
- When a different person signs in on the same device, the stored copy is wiped first, including any edits the previous person had not sent.
- Checked again on arrival
- Edits made offline are checked against the person’s role when they reach the server, the same as edits made online.
Getting your data out
The records a crew collects leave DatumPro in formats other tools open.
- Reports as CSV or Excel
- Reports, including the fields you define, export as CSV or XLSX, with dates, decimals and units in your display format.
- KMZ for mapping tools
- The map exports as KMZ for Google Earth and other mapping tools, with each feature’s attributes and photos.
- PDF sheets and map books
- Save the current map view as a PDF, or produce a map book: an overview, then detail sheets at a fixed scale wherever work has been drawn, with an index when there is more than one sheet.
Where it runs
- Microsoft Azure
- The hosted DatumPro services and the Keycloak sign-in server run on Microsoft Azure.
- Encrypted in transit
- Connections to the hosted service use HTTPS.
This website
What this site does with what you send it.
- Where form messages go
- What you send through a form is stored on this website’s own server. A copy may also be emailed to our team. Your browser sends nothing to a third-party service.
- Visits counted without cookies
- Visits are counted per page and per day, with no cookie, and no IP address or browser details kept. If your browser sends Global Privacy Control or Do Not Track, the visit is not counted.
- No third-party scripts
- Every script, font, image and video on this site is served by this site. No analytics, advertising or chat service is loaded.
Doing a security review?
If your review needs more than this page, send us your questions or your own questionnaire.
Send your security questionsSee it against your own build
A demo runs on your data shape: your tools, your attributes, one of your projects. Thirty minutes, no slide deck.