Security & Trust

Built for teams who have to answer to someone.

Field data often ends up in front of auditors, regulators, or a procurement team asking hard questions. Formulate is built so the honest answer is straightforward. Here is how access, devices, and sessions are protected.

Multi-factor authentication

Turn on time-based one-time codes (TOTP) for the web back office, the same kind your authenticator app already generates. Each tenant sets its own enforcement policy, so you can require MFA for everyone, or start with admins and roll it out from there.

Trusted devices only

A device has to be approved by an administrator before it can connect. Lost phones and unknown hardware do not get a foot in the door, and you can see and revoke what is authorised at any time.

Hardened mobile sessions

Mobile access runs on short-lived tokens rather than a login that lasts forever. Every time a session refreshes, Formulate re-checks that the account is still active and not locked out, so revoking access takes effect quickly rather than eventually.

People see what their role allows, and no more

Group permissions into roles, then assign people to them. Access to submissions and customer data is scoped by those roles, so a contractor, a regional manager, and a head-office administrator each see the slice of data that belongs to them. Change a role once and everyone in it updates together. Formulate is modular too: we enable the modules your tenant needs.

Built and hosted in the UK

Formulate is made by Triangle Software, a UK company, and hosted in the UK. For public sector and regulated buyers, that is not a box we tick as an afterthought. It is the default, and we can talk you through hosting specifics for your procurement checklist.

Compliance
The record-keeping regulators and auditors expect, built in.

Security is not just about who gets in. It is about being able to show, months later, exactly what was recorded, by whom, and when. Formulate keeps that evidence as a matter of course.

Full audit trail with timestamps and decisions on every submission
Mandatory field enforcement, so records cannot be left half-complete
Digital signatures with name, date, and a tamper-evident audit record
Every submission tagged with GPS location and the user who filed it
Role-scoped access, so people only reach the data they are cleared for
Sign-in & Device Authorisation
Multi-factor authentication and device authorisation screens
UK built & hosted
Encrypted in transit
Per-tenant data isolation
MFA & trusted-device enforcement

Sending us your procurement questions is the fastest way to real answers.

Tell us what your security or IT team needs to sign off, and we will walk you through it properly rather than pointing you at a PDF.