Field data often ends up in front of auditors, regulators, or a procurement team asking hard questions. Formulate is built so the honest answer is straightforward. Here is how access, devices, and sessions are protected.
Turn on time-based one-time codes (TOTP) for the web back office, the same kind your authenticator app already generates. Each tenant sets its own enforcement policy, so you can require MFA for everyone, or start with admins and roll it out from there.
A device has to be approved by an administrator before it can connect. Lost phones and unknown hardware do not get a foot in the door, and you can see and revoke what is authorised at any time.
Mobile access runs on short-lived tokens rather than a login that lasts forever. Every time a session refreshes, Formulate re-checks that the account is still active and not locked out, so revoking access takes effect quickly rather than eventually.
Group permissions into roles, then assign people to them. Access to submissions and customer data is scoped by those roles, so a contractor, a regional manager, and a head-office administrator each see the slice of data that belongs to them. Change a role once and everyone in it updates together. Formulate is modular too: we enable the modules your tenant needs.
Formulate is made by Triangle Software, a UK company, and hosted in the UK. For public sector and regulated buyers, that is not a box we tick as an afterthought. It is the default, and we can talk you through hosting specifics for your procurement checklist.
Security is not just about who gets in. It is about being able to show, months later, exactly what was recorded, by whom, and when. Formulate keeps that evidence as a matter of course.
Tell us what your security or IT team needs to sign off, and we will walk you through it properly rather than pointing you at a PDF.