Security & sovereignty

Your data stays yours

GeoMate is built local-first: your geoscience database lives on your infrastructure, works offline, and never leaves your environment unless you explicitly move it. This page sets out how that is enforced, what the platform protects, and what remains your responsibility.

01Architecture and data sovereignty

  • The master database — MS Access or SQL Server — is created and stored on your own machines or servers. It is the single source of truth and is fully operational with no network connection.
  • The optional server backend is self-hostable: you may run it inside your own network or private cloud, under your own security policy. It is a mirror, never a dependency.
  • The web companion is read and analytics oriented: it never writes to the master database.
  • There is no silent telemetry of your geological data. Nothing about your holes, assays or interpretations is transmitted to the publisher.

02Access control

  • User accounts are managed inside the platform, with permissions granted by role: read, capture, correct, validate, administer.
  • On Access deployments, a dedicated security manager governs database access and monitors it. On SQL Server, GeoMate builds on the instance’s own authentication and roles, so your DBA policy continues to apply.
  • Sensitive operations — schema changes, bulk correction, deletion — are restricted to administrator roles and recorded.

03Traceability and audit

  • History is append-only: a correction adds a record, it does not overwrite the past. Every value can be traced back to who entered it, when, and what it replaced.
  • Validation rules, standards, blanks and duplicates feed an audit report designed for competent-person review under JORC and NI 43-101.
  • The audit trail is exportable, so it can be handed to an auditor without giving access to the production database.

04Licensing under your control

  • Licences are granted per named seat. An administrator can grant, suspend or revoke a seat without waiting for the publisher.
  • Key validation cross-checks offline on the desktop, so a site with no connectivity is never locked out of its own data.

05Field synchronisation

  • The Android field application works offline by design. Forms are generated from the project package, so the field schema always matches the office.
  • Synchronisation runs over WiFi, USB or a direct hotspot between your own devices — no internet route is required, which matters on sites with no coverage or a restrictive network policy.
  • Where the optional server backend is used, only changed records cross the wire, over an encrypted transport.

06Encryption, backup and continuity

  • Because the database is yours and sits in your environment, encryption at rest is provided by the mechanisms you already operate — full-disk encryption on workstations, Transparent Data Encryption or equivalent on SQL Server. GeoMate does not interfere with them.
  • Data is stored in native, documented formats. If you stop using GeoMate, your database remains readable with standard tools: there is no proprietary lock-in and no export ransom.
  • Backup remains under your control — which is the point of a local-first design. We recommend scheduled backups, an off-site copy and a restore test at least once per campaign.

07This website and its services

  • This site is served exclusively over HTTPS with strict transport security and a content security policy restricting executable sources. Forms are protected by anti-spam verification and processed by isolated serverless functions.
  • Provider credentials are held in the hosting platform’s application settings and never appear in source code. The site collects commercial contact details only — never your project data.
Shared responsibility

No publisher secures a production system on its own. Here is the split, stated precisely — enough to answer an IT security questionnaire with no grey areas.

What we handle What is yours
Application security, role and permission model, audit trail integrity, licence validation. Operating-system and database hardening, patching, physical and network access to the machines hosting the database.
Corrective maintenance and security fixes published for the duration of your licence. Deploying published updates, and keeping Windows, Access or SQL Server supported and up to date.
Documented native formats, exportable audit trail, no lock-in. Backup policy, off-site copies, restore tests, and retention of your own data.
Account and seat management features, and support in using them. Who you grant a seat to, when you revoke it, and the internal segregation of duties.
Reporting a vulnerability

If you believe you have found a vulnerability, report it privately rather than publicly. Describe the affected component, the steps to reproduce and the observed impact. We acknowledge every report within five (5) business days, keep you informed of the fix, and will not take action against research carried out in good faith, without data exfiltration or service disruption.

admin-softteam@geomate-solutions.com

Request a free trial