---
title: "Security Information FieldBuddy"
canonical: "https://help.fieldbuddy.com/space/FBDOCS/5239341064/Security%20Information%20FieldBuddy"
format: markdown
---
At FieldBuddy, security relies mainly on the Salesforce platform. In this document we list our security information in four topics. 

## Application Security

FieldBuddy is an [application](https://developer.salesforce.com/docs/atlas.en-us.packagingGuide.meta/packagingGuide/about_managed_packages.htm) on the [Salesforce platform](https://www.salesforce.com/eu/products/salesforce-platform/). The FieldBuddy application does not use any external FieldBuddy servers to host or run the application. No servers are owned by FieldBuddy. All data and source code resides within the Salesforce cloud.

Salesforce has dedicated website about how it organizes its security:

- [https://security.salesforce.com/](https://security.salesforce.com/)

The certifications that Salesforce owns can be found here:

- [https://compliance.salesforce.com/en](https://compliance.salesforce.com/en)

The stability of the platform can be monitored here:

- [https://trust.salesforce.com/](https://trust.salesforce.com/)

Our source code has passed the security review. This is a review process that is done by the Salesforce security team. More information about the security review can be found [here](https://developer.salesforce.com/docs/atlas.en-us.packagingGuide.meta/packagingGuide/security_review_overview.htm).

On the [Appexchange](https://appexchange.salesforce.com/appxListingDetail?listingId=a0N30000008ZZkbEAG) our application is listed. This is only possible if the application has passed the security review.

## Customers data

By default, FieldBuddy does not have access to any data of the customer. The data resides within the [organisation](https://help.salesforce.com/s/articleView?id=sf.glossary.htm&type=5#o) of the customer and the customer owns the credentials of the System Administrator account(s).

Customers are responsible for their data, including back-ups.  There are [standard](https://help.salesforce.com/s/articleView?id=000386692&language=en_US&type=1) ways to back-up data or custom solutions.

Customers can temporarily share their access with FieldBuddy in case of required support. This is something a System Administrator explicitly chooses to do and is always temporarily. 

## Company security

At FieldBuddy our employees use a Sigle Sign On(SSO) application to access our main applications. This SSO-solution has MFA enabled. 

We do not have any (local) hosted servers that are used to develop FieldBuddy. 

The source code of the application is hosted within a Salesforce organisation. Only selected users access to this organisation. 

Back-ups of the source code are done via a cloud GIT solution. The development-team has access to this repository. 

Passwords are randomly generated and stored in a password manager. 

Our files are stored in a cloud filestorage solution that is [fully encrypted](https://support.box.com/hc/en-us/articles/360044194533-Data-Encryption-at-Box). 

## Security breaches

In case of an attack of ransomware or a computer virus on FieldBuddy employees, this will not affect the application or the source code of the application. Due to the fact that the source code is hosted within a Salesforce organisation.

Salesforce has a extended [document](https://compliance.salesforce.com/en/documents/a006e00000yVFFQAA4) in how it protects itself of ransomware. 

> ℹ️ Questions? Contact our support team.