1. Reporting a problem
If you find a security problem in FIELDFOLIO, please tell us. Email [email protected] with a clear description, the steps to repeat it, and what you saw. Use the subject line “Security report”. If you can, include the page or feature, your browser or device, and any screenshots. Please do not send real customer data in a report.
We aim to reply within 5 business days, keep you updated, and tell you when it is fixed. We may ask for more detail.
2. In scope
- fieldfolio.io, including the website under /site/ and the web app under /app/;
- the iOS and Android FIELDFOLIO apps;
- the sign-in, account deletion, and contact form functions that run on our Supabase project.
Examples of what we want to hear about: a way to read or change another user’s jobs, photos, or share links; a way to skip plan limits or crew seat limits; a sign-in or password reset flaw; injection or cross-site scripting; and exposed secrets.
3. Out of scope
- denial of service, load tests, or anything that degrades the service for other people;
- social engineering, phishing, or physical attacks on us, our providers, or our users;
- spam or email issues that are not a security flaw (for example, missing records on a domain that cause no harm);
- findings that need a rooted or jailbroken device, or an already compromised device or account;
- problems in the services of Cloudflare, Supabase, Stripe, Resend, Forward Email, Apple, or Google that are not caused by how we use them. Report those to the provider;
- automated scanner output with no proof that it can be used.
4. What we ask of you
- Test only with accounts you own, or with permission.
- Do not access, change, or delete other people’s data. If you hit someone else’s data by accident, stop and tell us.
- Do not make us pay: avoid heavy traffic, mass emailing, or spam through our forms.
- Give us a reasonable time to fix the problem before you tell anyone else. We ask for 90 days, and we will tell you if we need more.
- Do not demand payment as a condition of reporting.
5. Good faith protection
If you follow this policy and act in good faith, we will not start legal action against you or ask law enforcement to, for the testing you did within this policy. This does not cover anyone else’s systems, and a third party could still act. If you are not sure whether something is allowed, ask first.
6. Rewards
We are a small team and do not have a paid bounty program at this time. We are glad to thank you by name in a thank-you note if you want, with your OK.
7. How we protect your data
We serve the site over HTTPS from Cloudflare Pages, send security headers and a restrictive content security policy, use Supabase authentication and row-level access rules for cloud data, and keep payment card handling with Stripe. No system is perfect. See the Privacy Policy and Terms and Conditions.
Updated Oct 1, 2026 (CT).