FieldScout

Security

Protection follows the work from sign-in through handoff.

Whether you work independently with Individual or share Jobs with an Agency team, FieldScout combines account, role, jurisdiction, transaction, and workflow boundaries to keep protected work with the authorized people responsible for it.

Core safeguards

Boundaries around access, data, and supported workflows.

FieldScout applies controls at the point where people sign in, open agency work, send requests, use source-backed features, or change paid access.

Access and identity

Who may access FieldScout and which actions they may perform.

Agency isolation
Agency membership checks prevent one agency from opening another agency’s account, records, or billing information.
Roles and jurisdiction
Role checks limit sensitive actions, while jurisdiction checks keep program sources and workflows within the agency’s assignment.
Authentication and recovery
Passwords are stored as one-way password hashes. Setup and recovery links are time-limited and single-use, and successful reset flows invalidate other outstanding recovery access supported by the account lifecycle.

Data and workflow boundaries

How requests, customer work, and source-backed features stay within their intended scope.

Browser and request safeguards
State-changing browser requests use CSRF protection. Signed webhooks use their own request-verification boundaries. Rate limits, bounded sessions, secure production cookies, restrictive browser policies, and safe error pages reduce common request and browser risks.
Protected customer work
Client last name and complete service or property address remain inside authorized agency workflows and are excluded from public and unrelated operational surfaces. Prepared Field Visits temporarily retain protected information on the device for use through coverage loss. Agency access is checked again before synchronization; conflicting edits are kept for review rather than silently overwriting the agency Job.
Source-backed workflow readiness
Customer WAP Chat remains off until eligible jurisdiction sources are indexed and verified. FieldScout must also enable source-backed access for that jurisdiction. Missing or unknown readiness fails closed.

Operations and trust

Verify first. Expose only what is needed.

Transaction, logging, and deployment boundaries protect the service without turning internal implementation details into customer promises.

01

Payment integrity

FieldScout sends a confirmed order to Stripe, verifies signed payment events, and applies accepted events idempotently before creating or changing paid access. FieldScout checkout does not collect raw card numbers.

02

Secrets and operational logs

Credentials, setup links, sessions, raw payment details, and protected customer identifiers are restricted from public pages, routine logs, unrelated telemetry, and review packages.

03

Production safeguards

FieldScout admits production releases only when required service, database, schema, storage, and application checks pass. Deeper operational health also tracks workers, queues, billing, email delivery, and durable customer work so failures can be surfaced to FieldScout operators.

Shared responsibility

Three agency practices that materially improve security.

  1. 01

    Use individual access

    Give each authorized person an individual account and remove access when it is no longer needed. Protect field devices with a screen lock. An offline device cannot immediately learn that access has been revoked. Sync needed entries before signing out, which removes local Field Visit copies.

  2. 02

    Keep sensitive data in supported places

    Keep passwords, payment details, secrets, and unnecessary household identity out of email and unsupported fields.

  3. 03

    Verify program requirements

    Use current governing material, required approvals, and qualified judgment for Weatherization decisions.

Report a concern

Report a security concern directly.

Describe the affected page or workflow and what you observed. Do not send passwords, secrets, raw card details, or unnecessary household information.