Galveston County · pilot network
Trust & method

SHOW THE WORK. NOT JUST THE PROMISE.

This is the proof room. It explains the provider states, privacy boundaries, ledger rules, payment gates and limitations behind ProvisionLoop so nobody has to trust a marketing sentence when the operating rule can be shown instead.

01 · IdentityWho is actually verified?
02 · PrivacyWho can see what?
03 · MoneyWhen can funding move?
04 · ProofWhat is allowed to count?

Providers mapped

Operator verified

Funding-enabled kitchens

Meals delivered (ledger)

The operating chain

REQUEST TO PROOF, WITHOUT EXPOSING A PERSON.

01

Private request

A household asks for food help through a private form. The request is never published, never shown to sponsors and never attached to a name in a public view.

02

Verified partner routing

An approved community partner reviews an assigned request using its own eligibility and safeguarding practices. Identifiable data stays behind the partner access boundary.

03

Kitchen capacity

A claimed and approved operator publishes usable capacity and its own posted meal cost. ProvisionLoop does not invent or mark up that price.

04

Volunteer & dispatch

Prep shifts and delivery runs expose only what the worker needs to complete the job. Public boards do not expose household identity.

05

Fulfillment verification

Operational states move through preparation and delivery before the loop can close. Payout logic is tied to fulfillment rather than a promise made at checkout.

06

Aggregate civic ledger

Closed outcomes create aggregate impact events. The public can inspect meals, geography and timing without seeing the person who received help.

Provider verification

THREE STATES. NO BLUR.

Visibility, operator verification and funding eligibility are separate facts. The interface and server rules should never collapse them into one badge.

Directory listing — not affiliated

A real local food program mapped from public information so people can find help. The organization has not partnered with or endorsed ProvisionLoop and cannot receive platform funding.

Operator verified

An operator claim has been reviewed and approved. The operator can control provider details and capacity, but verification by itself does not make the provider funding-enabled.

Funding enabled

A verified operator that has also completed the required payout-readiness state. Server-side funding checks enforce this state rather than relying on a hidden button in the UI.

Unclaimed listings stay useful for discovery in Find food help, but they are never fundable. A funding attempt against an ineligible kitchen is rejected by server-side eligibility checks.

How impact counts are created

A meal counts late, on purpose.

  • Funding events should enter the real ledger only from confirmed payment events, not intents or abandoned checkout sessions.
  • Delivery events should enter only after the fulfillment workflow reaches the delivered state.
  • Sandbox/test activity is kept separate from real civic totals.
  • Payout eligibility is coupled to fulfillment state so the product does not describe money as earned solely because checkout began.

Recipient privacy boundary

Public proof does not need public people.

  • Household requests are not public content.
  • Approved partners receive only referrals assigned within their governed workspace.
  • Public volunteer boards show operational drop-off areas and windows rather than recipient identity.
  • Public civic reporting is aggregate and suppresses small cohorts.

Money boundaries

WHEN MONEY IS ALLOWED TO MOVE.

Payment actions re-check the current required legal acceptance on the server.
A kitchen must be approved, active, claimed and payout-ready before it can be funded.
Recurring sponsorship checkout pauses when the network has no funding-enabled kitchen capacity.
ProvisionLoop pilot payments are not represented as tax-deductible charitable donations.

What we refuse to claim

THE HONEST LIST.

We do not call a directory listing a partner, sponsor or affiliate unless the relationship has actually been established.
We do not claim tax-deductible donation status or charitable registration for ProvisionLoop payments.
We do not claim certifications, audits, food-safety accreditation or regulatory approval that have not been independently established.
We do not inflate public impact with demo or projected numbers; sandbox activity is separated from real civic totals.
We do not turn a delivered meal into a broader social-outcome claim. A completed meal is reported as a completed meal.
We do not publish recipient names or identifiable household details in the public ledger.

Pilot limitations

WHAT IS NOT PROVEN YET.

01

This is a Galveston County pilot. Geographic coverage and verified provider capacity are still limited.

02

The complete real-money Stripe lifecycle still requires operational certification with live credentials, signed webhooks and an actual payout-enabled provider before it should be described as proven end to end.

03

Directory details come from public sources and can become stale. People should confirm hours and eligibility with the organization directly.

04

The civic ledger is intentionally small and privacy-suppressed; it is not a substitute for a countywide needs assessment.

For listed organizations

CLAIM IT. CORRECT IT. OR REMOVE IT.

A public directory listing does not mean you signed up. Operators can claim a listing through verification, and any listed organization can request a correction or removal without first becoming a ProvisionLoop partner.