Security

Practical controls, honestly described.

Fielduro protects business and customer documents with layered access, storage, delivery, and monitoring controls. We publish only controls we can verify.

Encrypted connections

Fielduro uses HTTPS to encrypt data in transit.

Per-account ownership

Supabase Row Level Security and server checks isolate each user's workspace.

Private payment proof

Optional payment proof is stored in private storage and accessed with short-lived signed URLs.

Controlled customer links

Customer links are random, expiring, and revocable.

Verified payment events

Stripe webhooks are signature-verified and live and sandbox modes remain separated.

Data control

Signed-in users can export stored data and permanently delete their account.

Minimized error monitoring

Sentry receives scrubbed diagnostics, no replay, no default PII, and only the user UUID when authenticated.

Secret management

Production secrets stay in deployment configuration, outside the source repository.

Responsible disclosure

Found a security problem?

Email security@fielduro.com with the affected URL, steps to reproduce, and potential impact. Do not access other users’ data, disrupt the service, or publicly disclose an issue before we can investigate.

Report a security issue