Skip to content
DatumPro

Security & data

Who sees what, and what gets recorded. As it works today.

How access, sign-in, record keeping and offline copies work in DatumPro now. What is not in place yet is listed at the end.

Who can see what

A role, given at a scope
Access is a role given to a person or a team at a scope, such as a client or a project, or across the whole organisation. The role applies there and to everything beneath it.
Checked by the server
Before the server returns or changes a client, project, job, map feature, catalogue or export, it checks the person’s role. The screen never decides on its own.
A job share is bounded by the job’s area
Share one job and the person reaches map features only inside that job’s area. The project’s layers and catalogue come with the share, so they have what they need to work.
Read-only viewers
By default, the Viewer role opens a shared map with no permission to change anything. Viewers sign in like everyone else: there is no public link to a map.
Crews change their own work
By default, a field crew member reads every feature their share reaches and adds new ones, but changes or deletes only the features they added.
You can only share what you hold
To give someone a role at a scope, you must already hold every permission in it there, so sharing cannot pass on more access than you have.

Signing in

Keycloak holds the accounts
Sign-in runs through Keycloak, which keeps user accounts and sign-in credentials in a database of its own, separate from project data.
Your company sign-in, if you want it
Keycloak can connect to your company’s identity provider, so people sign in with the account they already have. Nothing is connected by default.

What is recorded

An append-only audit trail
By default, creating, changing or deleting a client, project, job, catalogue or map feature is recorded: who did it, when, and what changed. Entries are only ever added; none is edited in place.
Where each map edit was made
Every map edit records the position of the device that made it, and how accurate that position was. That position is kept in the audit record, not shown in the feature’s details. The map does not accept an edit from a device that cannot give its position.
Edits are timed by the server
The time of an edit comes from the server’s clock, not the tablet’s, so an edit made offline is timed when it reaches the server.
Where people are on the map
By default, while the map is open, the device also reports its position to the server every 30 seconds. Anyone who can open the project sees where colleagues were last seen in the past 12 hours and the route each took today; someone who manages the project can look back up to 30 days.

Working offline

The map keeps working without signal because the work is stored on the device.

Edits wait on the device
Edits are saved in the browser’s storage on the tablet or laptop first, then sent to the server when there is a connection. Projects opened on the device are kept there for offline use.
Not encrypted by DatumPro
DatumPro does not add its own encryption to that stored copy. Protect field devices with the device’s own encryption and a screen lock.
A new person starts clean
When a different person signs in on the same device, the stored copy is wiped first, including any edits the previous person had not sent.
Checked again on arrival
Edits made offline are checked against the person’s role when they reach the server, the same as edits made online.

Getting your data out

The records a crew collects leave DatumPro in formats other tools open.

Reports as CSV or Excel
Reports, including the fields you define, export as CSV or XLSX, with dates, decimals and units in your display format.
KMZ for mapping tools
The map exports as KMZ for Google Earth and other mapping tools, with each feature’s attributes and photos.
PDF sheets and map books
Save the current map view as a PDF, or produce a map book: an overview, then detail sheets at a fixed scale wherever work has been drawn, with an index when there is more than one sheet.

Where it runs

Microsoft Azure
The hosted DatumPro services and the Keycloak sign-in server run on Microsoft Azure.
Encrypted in transit
Connections to the hosted service use HTTPS.

This website

What this site does with what you send it.

Where form messages go
What you send through a form is stored on this website’s own server. A copy may also be emailed to our team. Your browser sends nothing to a third-party service.
Visits counted without cookies
Visits are counted per page and per day, with no cookie, and no IP address or browser details kept. If your browser sends Global Privacy Control or Do Not Track, the visit is not counted.
No third-party scripts
Every script, font, image and video on this site is served by this site. No analytics, advertising or chat service is loaded.

Doing a security review?

If your review needs more than this page, send us your questions or your own questionnaire.

Send your security questions

See it against your own build

A demo runs on your data shape: your tools, your attributes, one of your projects. Thirty minutes, no slide deck.

Book a demo