plotbook.

Trust & security

Your sites' data,
properly looked after.

A plot's history — its photos, its snags, its sign-offs — is a record people rely on. We treat it that way: encrypted, access-controlled, monitored, and backed up. Here's how, in plain terms.

Encrypted in transit & at rest Least-privilege access UK/EEA hosting

How we protect data

Security built in, not bolted on.

The same care that goes into the plot model goes into keeping it safe. No surprises, no theatre.

Encryption everywhere

Data is encrypted in transit with TLS and at rest with industry-standard ciphers. Photos and job data are never stored in the clear.

Least-privilege access

People and services get only the access they need. Internal access is role-based, logged, and reviewed — and tied to your company's boundaries.

Monitoring & alerting

We watch the platform continuously for anomalies and errors, with alerts that page a human when something needs attention.

Backups & recovery

Job data is backed up regularly with tested restore procedures, so a bad day never becomes a lost plot history.

Secure by default

Strong authentication, sensible session handling, and dependencies kept patched. The safe path is the default path.

Offline that's still safe

The Field app caches work on-device so trades aren't blocked by signal — held securely and synced over an encrypted channel.

Data handling

Your company controls its job data; Plotbook processes it on your behalf. We collect the minimum needed to run the Service, and we do not sell data or use your sites' photos, snags or sign-offs to train machine-learning models. The detail of what we collect and why is in our privacy notice.

Hosting & location

Plotbook runs on reputable cloud infrastructure with data held in the UK/EEA where possible. Infrastructure is isolated between environments, and production access is restricted and audited. Where a supplier processes data outside the UK/EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement.

Access control

Access follows least privilege. Internal access is role-based and logged; production secrets are managed centrally and rotated. Within the product, your company's administrators control who can see and do what across your sites and plots.

Secure development

Security is part of how we build: peer-reviewed changes, automated dependency checks, and a staged release process. We keep our stack patched and treat security fixes as priority work.

Report a vulnerability

If you believe you've found a security issue, we want to hear from you. Email security@plotbook.co.uk with enough detail to reproduce it. Please give us a reasonable window to investigate and fix before any public disclosure — we'll keep you updated, and we're grateful for responsible reports.

Doing security due diligence?

We're happy to walk your team through our practices and answer a questionnaire as part of onboarding.