How your data is protected
- Every connection to the platform runs over TLS
- Tenant isolation fails closed at the framework layer, so a chamber's data is scoped by default rather than by a check someone could forget
- Passwords are hashed, never stored
- Credentials and integration tokens are encrypted at rest
- Card data never touches our servers: every processor uses hosted payment fields
The server layer
- A web application firewall and continuous malware scanning run at the host
- The server follows an automatic patching cadence
- Access is limited to named individuals, over key-based SSH only
Backups
Database snapshots run hourly and file archives run every four hours. Both are encrypted, and full-image server backups are held offsite as well. Restores are tested, not assumed to work.
Monitoring
Checks run continuously against the platform, with automatic alerting to the team the moment anything degrades. Current status is public at /status.
If something goes wrong
We investigate immediately on detecting any suspected incident. If we confirm that chamber or member data was affected, we notify every affected chamber by email within 72 hours of that confirmation, with what happened, what data was involved, what we did about it, and what we recommend you do next.
We cooperate fully with applicable notification laws. If you need to reach us about a security matter directly, use [email protected], the same inbox that handles every other platform question.
Ask us anything
Questions about security belong before a signature, not after. Ask us anything: [email protected].