Payment integrity
FieldScout sends a confirmed order to Stripe, verifies signed payment events, and applies accepted events idempotently before creating or changing paid access. FieldScout checkout does not collect raw card numbers.
Security
FieldScout combines agency, role, jurisdiction, transaction, and workflow boundaries to keep protected work with the authorized people responsible for it.
Core safeguards
FieldScout applies controls at the point where people sign in, open agency work, send requests, use source-backed features, or change paid access.
Who may enter the workspace and which actions they may perform.
How requests, customer work, and source-backed features stay within their intended scope.
Operations and trust
Transaction, logging, and deployment boundaries protect the service without turning internal implementation details into customer promises.
FieldScout sends a confirmed order to Stripe, verifies signed payment events, and applies accepted events idempotently before creating or changing paid access. FieldScout checkout does not collect raw card numbers.
Credentials, setup links, sessions, raw payment details, and protected customer identifiers are restricted from public pages, routine logs, unrelated telemetry, and review packages.
The /readyz endpoint reports ready when database and schema access and required durable source storage pass. Separate production launch checks cover account email delivery, sender identity, billing and webhook configuration when enabled, and other deployment safeguards.
Shared responsibility
Give each authorized person an individual account and remove access when it is no longer needed.
Keep passwords, payment details, secrets, and unnecessary household identity out of email and unsupported fields.
Use current governing material, required approvals, and qualified judgment for Weatherization decisions.
Report a concern
Describe the affected page or workflow and what you observed. Do not send passwords, secrets, raw card details, or unnecessary household information.