How Formulate protects your data

Procurement and audit teams ask the same questions about access, devices and data location. This page is written to be forwarded to them.

Multi-factor authentication

Turn on time-based one-time codes (TOTP) for the web back office, the same kind your authenticator app already generates. Each tenant sets its own enforcement policy, so you can require MFA for everyone, or start with admins and roll it out from there.

Trusted devices only

A device has to be approved by an administrator before it can connect. Lost phones and unknown hardware do not get a foot in the door, and you can see and revoke what is authorised at any time.

Hardened mobile sessions

Mobile access runs on short-lived tokens rather than a login that lasts forever. Every time a session refreshes, Formulate re-checks that the account is still active and not locked out, so revoking access takes effect quickly rather than eventually.

People see only what their role allows

Group permissions into roles, then assign people to them. Access to submissions and customer data is scoped by those roles, so a contractor, a regional manager, and a head-office administrator each see the slice of data that belongs to them. Change a role once and everyone in it updates together. Formulate is modular too: we enable the modules your tenant needs.

Built and hosted in the UK

Formulate is made by Triangle Software, a UK company, and hosted in the UK. For public sector and regulated buyers, we can talk you through where the data lives and who can reach it.

Encrypted in transit
Per-tenant data isolation
An audit trail on every submission

Months later you may need to show exactly what was recorded, by whom, and when. Formulate keeps that evidence as a matter of course.

Full audit trail with timestamps and decisions on every submission
Mandatory field enforcement, so records cannot be left half-complete
Digital signatures with name, date, and a tamper-evident audit record
Every submission tagged with GPS location and the user who filed it
Role-scoped access, so people only reach the data they are cleared for
Sign-in & Device Authorisation
Multi-factor authentication and device authorisation screens

Send us your procurement questions

Tell us what your security or IT team needs to sign off and we will work through it with you.