IPSRM Field: Security and data
IPSRM Field is a web app that keeps your assessments on your own device. This statement is for practitioners and for clients’ security teams.
What is stored, and where
Your engagements, findings, evidence and photos are stored in the browser’s storage on your device, for IPSRM Field’s website only. They are not stored on any server, ours or anyone else’s.
The app asks the browser to keep this data permanently. Settings › Storage and backups shows whether the browser has agreed. Without that, a browser may clear website data when the device is short of space, or after a period without use.
Safari and an app added to the Home Screen keep separate storage, even on the same iPad. Work entered in one is not visible in the other.
Settings, including your practitioner and firm details, the backup history and the licence, are stored on your device too. The backup history holds no client or site names.
What leaves the device
Nothing, except the licence check. When you enter a licence key, and about once a week afterwards, or when you tap Check licence now, IPSRM Field sends the key and its product identifier to Gumroad, our sales platform, to confirm the licence is valid. No assessment data is sent. Gumroad’s reply, including the name and email on the purchase, is kept on the device only.
The app’s security policy allows no other outward connection. There are no analytics, no advertising, no cookies, no third-party scripts and no externally loaded fonts.
Backups, reports and exports leave the device only when you save them and choose where they go.
Backups
Only IPSRM Field’s own backups are a dependable way to keep your work. Your device’s own backups (iCloud, or a backup to a computer) may not include browser storage, so do not rely on them.
A backup can be protected with a passphrase of at least 12 characters. Its whole contents, photos included, are then encrypted (AES-GCM, 256-bit, with the key derived from the passphrase by PBKDF2-SHA-256, at least 600,000 iterations). The passphrase is never stored and cannot be recovered.
When an engagement carries a protective marking, its backups and exports of original photos must be protected. The marking is shown on the outside of the protected file, so its handling requirement is visible before it is opened, and the file name never includes the organisation or site.
The app lock (optional)
With the app lock switched on in Settings, every engagement and photo is stored encrypted on your device, and IPSRM Field asks for your passphrase when it opens, after a period without use, and when you tap Lock.
The licence stays readable so the licence check still works. It holds no assessment data.
A forgotten passphrase cannot be recovered: there is no server that could. The only way forward is to erase the device’s data and restore from backups.
Reports
Word reports, the Excel register and PDFs saved from Word are not encrypted. Store and send them as the engagement’s protective marking and your client’s requirements demand. The marking prints on every page of the report and every sheet of the register.
A sealed issue carries a verification code. Entering the code in IPSRM Field shows the sealed record of findings, scores, tiers and the Overall Exposure Position, so those figures in any copy of the report can be checked against it.
Photos and dictation
Photo location is off by default for each engagement. When it is on, the location is kept in the evidence record only and never appears in report images. Photos chosen from your Photos library keep the details they carry, so the original may include where it was taken; working copies and report images never include location.
On sensitive sites, take photos with the app’s camera rather than choosing them from the Photos library.
You can dictate into any text box using your device’s keyboard microphone. Dictation is provided by your device’s keyboard, not by IPSRM Field. Depending on the device, language and settings, it may be processed on the device or by the device maker’s servers. Check your device’s dictation settings before using it on sensitive sites.
On the device: what you are responsible for
Protect the device with a passcode and a short Auto-Lock time.
The iPad’s app switcher may show the last screen you viewed. On sensitive sites, switch on the privacy screen, which keeps your work out of the app switcher once it has covered the screen, and close IPSRM Field from the app switcher before leaving the iPad unattended.
Keep current backups of every engagement, stored as your client’s requirements demand.
Before handing a device on, use Settings › Storage and backups › Erase this device.
The code and the accounts behind it
Hosted on Cloudflare Pages, with no server-side code. The code is held in a private GitHub repository; it is published only from a protected release branch, after release checks. Settings › About this version shows the exact version and its code reference.
The accounts behind the app (code, hosting, sales and email) are protected with two-factor authentication.
Tested on
Tested on iPad (iPadOS 26.6.1, Safari and the Home Screen app) and on Windows 11 with Edge and Google Chrome. Other current browsers are expected to work but have not yet been tested.
Questions
Questions, or to report a security concern: support@ipsrm.org.