Data security
Thingsform Data security sets the ground rules. Two-factor authentication, IP restriction, session lifetime, encryption of sensitive fields and blocking of unauthorised exports. The data catalogue lists what you hold, including what was collected offline in the field.
- MFA / IP policies
- Field encryption
- Export control
What Data security brings
MFA / IP policies
Field encryption
Export control
Data security in your workflow
Data security does not work in isolation: every action can feed the platform's other modules.
Data security → Data Hub
Receive, clean and route incoming data, with its provenance kept.
Explore Data HubFrequently asked questions about Data security
Which modules does Data security work with?
Data security connects natively to GDPR, Audit, Data Hub and API & Tokens. Data flows from one module to the next with no export or integration to set up.
What does sensitive-field encryption do?
It protects specific columns — an identifier, a personal detail — rather than all or nothing. The rest of the account stays normally usable, so security is not abandoned for convenience.
Can I enforce two-factor authentication?
Yes, through a policy applied to the organisation, with IP restrictions and session duration limits. A policy set once beats an instruction repeated in meetings.
Can exports of data be prevented?
They can be controlled, profile by profile. This is often the weak point: a perfectly partitioned account from which anyone can pull a complete file.
Which plan includes Data security?
Included from the Pro plan. Combined with Audit, it lets you show not only the rules you set but that they were actually applied.