Encrypted connections
Fielduro uses HTTPS to encrypt data in transit.
Security
Fielduro protects business and customer documents with layered access, storage, delivery, and monitoring controls. We publish only controls we can verify.
Fielduro uses HTTPS to encrypt data in transit.
Supabase Row Level Security and server checks isolate each user's workspace.
Optional payment proof is stored in private storage and accessed with short-lived signed URLs.
Customer links are random, expiring, and revocable.
Stripe webhooks are signature-verified and live and sandbox modes remain separated.
Signed-in users can export stored data and permanently delete their account.
Sentry receives scrubbed diagnostics, no replay, no default PII, and only the user UUID when authenticated.
Production secrets stay in deployment configuration, outside the source repository.
Responsible disclosure
Email security@fielduro.com with the affected URL, steps to reproduce, and potential impact. Do not access other users’ data, disrupt the service, or publicly disclose an issue before we can investigate.