Security

Security and responsible disclosure.

Report suspicious activity, access concerns, or suspected security vulnerabilities. Do not send passwords, recovery codes, payment card numbers, API keys, private credentials, full client files, or unnecessary personally identifiable information by email.

Security concerns

Report security issues here.

Use this page for suspicious account activity, access concerns, shared-login concerns, exposed records, or suspected vulnerabilities. For general login help, setup, billing, or workflow questions, use Support.

Suspicious account activity

Report unexpected login activity, unknown access, account changes you did not request, or signs that a workspace, record, or user account may be exposed.

Access or permission concern

Report user access that appears incorrect, access that should be removed, shared-login concerns, or a role or workspace permission that may expose records.

Responsible disclosure

Report a suspected vulnerability, exposed endpoint, broken access control, data exposure, or other issue that could affect FieldScout accounts, agency records, or service integrity.

Security reports

Send enough detail to help review the issue.

Include only the information needed to understand and review the issue.

Helpful details

Include the affected page or workflow, the date and time noticed, browser or device details if relevant, and a concise description of the concern.

Do not include secrets

Do not send passwords, recovery codes, API keys, payment card numbers, private credentials, full client files, or unnecessary personally identifiable information by email.

Responsible testing

Do not disrupt service, access another agency workspace, download records, or test against data you are not authorized to use.

Security boundaries

Security boundaries stay clear.

FieldScout helps protect accounts and workspace access, but agency approval, program authority, field judgment, and final compliance review remain with the agency.

Expected follow-up

FieldScout may follow up for more detail, confirm receipt when appropriate, and prioritize reports based on severity, affected accounts, and risk to agency records.

Payment safety

Checkout runs through Stripe. Card numbers are not requested by email.

Protected routes

Workspace access uses assigned accounts and protected routes for field, review, and admin records.