LocateIQ LocateIQ

Security

Last Updated: April 9, 2026

LocateIQ is designed to keep your survey data secure. This page describes the security architecture, data handling practices, and protections built into the app and platform.

Pass-Through Architecture: LocateIQ does not host, process, or retain customer survey data on LocateIQ-operated infrastructure. Survey data is stored on-device and syncs directly to your existing ArcGIS Online or Subsurface Maps account. The systems that hold your data (Esri, Diamond Maps) maintain their own SOC 2 and security certifications.

No Central Data Store

LocateIQ does not operate a central server that stores your survey data. Your maps, points, lines, and photos stay on your device and in your own mapping accounts.

Direct-to-Provider Sync

Data syncs directly between your device and ArcGIS Online or Subsurface Maps. LocateIQ never sits between you and your mapping provider.

On-Device Processing

GPS data, BLE sensor readings, photo analysis, and coordinate transformations all happen locally on your device. Nothing is sent to LocateIQ.

OAuth Authentication

LocateIQ never sees or stores your ArcGIS password. Authentication uses industry-standard OAuth 2.0 with token-based sessions.

Data Flow Architecture

Understanding where your data goes is the foundation of trust. Here is how data moves through LocateIQ:

Your Device ├── GPS/GNSS Receiver ──→ Coordinates stay on device ├── Survey Locator (BLE) ──→ Measurements stay on device ├── Camera ──→ Photos stored locally in project folder ├── Local SQLite DB ──→ All survey data cached on device ├── Sync (your choice) ──→ ArcGIS Online (your account) ├── Sync (your choice) ──→ Subsurface Maps (your account) └── NTRIP corrections ──→ Your NTRIP provider (you configure) LocateIQ servers receive: None of the above

Authentication & Credentials

ArcGIS Sign-In

Subsurface Maps Sign-In

LocateIQ Account

On-Device Data Security

Network Security

Bluetooth Security

Multi-Company Data Isolation

For organizations using the LocateIQ cloud platform:

Encryption

Data at Rest

Data in Transit

Offline Access PIN

Data Deletion & Retention

Compliance Posture

LocateIQ's pass-through architecture means customer survey data never resides on LocateIQ-operated infrastructure. The services that store your data — Esri ArcGIS Online and Diamond Maps (Subsurface Maps) — maintain their own compliance certifications.

Permission Usage Summary

Permission Purpose When Active
Location (Precise) GPS coordinates for survey points While surveying
Location (Background) Maintain GPS during BLE device connection Only when GNSS device connected
Bluetooth Connect GNSS receivers & survey loggers When user connects a device
Camera Capture photos as map feature attributes When user taps photo button

All permissions can be denied. The app continues to function with reduced capabilities and explains what features require each permission.

Responsible Disclosure

If you discover a security vulnerability in LocateIQ, please report it to us directly. We take all reports seriously and will respond promptly.

Security Contact:
Email: brent@subsurfacesolutions.com