FieldScout

Security

Protection follows the work from sign-in through handoff.

FieldScout combines agency, role, jurisdiction, transaction, and workflow boundaries to keep protected work with the authorized people responsible for it.

Core safeguards

Boundaries around access, data, and supported workflows.

FieldScout applies controls at the point where people sign in, open agency work, send requests, use source-backed features, or change paid access.

Access and identity

Who may enter the workspace and which actions they may perform.

Agency isolation
Agency membership checks prevent one agency from opening another agency’s workspace, records, or billing information.
Roles and jurisdiction
Role checks limit sensitive actions, while jurisdiction checks keep program sources and workflows within the agency’s assignment.
Authentication and recovery
Passwords are stored as one-way password hashes. Setup and recovery links are time-limited and single-use, and successful reset flows invalidate other outstanding recovery access supported by the account lifecycle.

Data and workflow boundaries

How requests, customer work, and source-backed features stay within their intended scope.

Browser and request safeguards
State-changing browser requests use CSRF protection. Signed webhooks use their own request-verification boundaries. Rate limits, bounded sessions, secure production cookies, restrictive browser policies, and safe error pages reduce common request and browser risks.
Protected customer work
Client last name and complete service or property address remain inside authorized agency workflows and are excluded from public and unrelated operational surfaces.
Source-backed workflow readiness
Customer WAP Chat remains off until eligible jurisdiction sources are indexed and verified and the agency’s explicit Admin States switch is on. Missing or unknown readiness fails closed.

Operations and trust

Verify first. Expose only what is needed.

Transaction, logging, and deployment boundaries protect the service without turning internal implementation details into customer promises.

01

Payment integrity

FieldScout sends a confirmed order to Stripe, verifies signed payment events, and applies accepted events idempotently before creating or changing paid access. FieldScout checkout does not collect raw card numbers.

02

Secrets and operational logs

Credentials, setup links, sessions, raw payment details, and protected customer identifiers are restricted from public pages, routine logs, unrelated telemetry, and review packages.

03

Runtime and launch readiness

The /readyz endpoint reports ready when database and schema access and required durable source storage pass. Separate production launch checks cover account email delivery, sender identity, billing and webhook configuration when enabled, and other deployment safeguards.

Shared responsibility

Three agency practices that materially improve security.

  1. 01

    Use individual access

    Give each authorized person an individual account and remove access when it is no longer needed.

  2. 02

    Keep sensitive data in supported places

    Keep passwords, payment details, secrets, and unnecessary household identity out of email and unsupported fields.

  3. 03

    Verify program requirements

    Use current governing material, required approvals, and qualified judgment for Weatherization decisions.

Report a concern

Report a security concern directly.

Describe the affected page or workflow and what you observed. Do not send passwords, secrets, raw card details, or unnecessary household information.