Security & trust

Your members trusted you with their information.

A chamber holds business contact details, payment records, and years of relationship history. This page says plainly how that data is protected — including the things we haven't done yet.

Encryption everywhere

  • All traffic is served over TLS 1.2+ with HSTS; there is no unencrypted path into the platform.
  • Data at rest is encrypted with AES-256 on managed, encrypted volumes.
  • Backups are encrypted with the same standard and stored separately from the primary database.

Payment data never touches us

  • Card and bank details are collected by Stripe directly and exchanged for a token.
  • Chamberzu stores the token and the last four digits — never a full card number, never a CVV.
  • Because full card data never enters our systems, your chamber's PCI scope stays as small as it can be.

Access control by construction

  • Every API request is authorised server-side against the caller's role — hiding a button is not a permission model.
  • Member portal accounts are scoped to a single member organization and cannot enumerate other members' records.
  • Chamber data is isolated per tenant; a query for one chamber cannot return another chamber's rows.

Operational discipline

  • Automated daily backups with documented, periodically exercised restore procedures.
  • Audit logging on authentication, permission changes, and financial records.
  • Dependency and container image scanning on every build, with patches applied on a defined cadence.
Access control, in the product

Roles you can actually see and set.

Permissions are not a bullet on a feature list. Every staff account carries a role, and the server checks it on every request — a committee volunteer can run their programme without ever seeing member financials.

See how member records are structured →

The Chamberzu staff users screen, listing each user with their assigned role.
Staff, finance, events and read-only roles, assigned per user.
Commitments

How we behave with your data.

Controls are table stakes. These are the policy choices behind them.

Your data is yours

You own every record you put into Chamberzu. You can export all of it at any time, in open formats, without asking us. We do not sell member data, and we do not use your members' information to market to them.

Deletion means deletion

Cancel and we delete your data within 90 days, backups included, unless you ask us to remove it sooner. We will send you a full export first.

Least-privilege internally

Access to production data is limited to the engineers who need it, requires multi-factor authentication, and is logged. Support staff work from the fewest privileges that resolve your ticket.

Subprocessors, listed

We use a short list of infrastructure and service providers — principally AWS for hosting, Stripe for payments, and SendGrid for transactional email. Each is contractually bound to protect data processed on our behalf, and we will provide the current list on request.

Incident response

We maintain a documented incident response process. If a breach affects your chamber's data, we will notify you directly with what happened, what was affected, and what we are doing about it — not a status page footnote.

Responsible disclosure

Found a vulnerability? Email us and we will acknowledge within two business days. We do not pursue legal action against researchers who report in good faith and give us reasonable time to fix the issue.

Not done yet

What we haven't finished.

Vendors rarely publish this list. We think a security page that only contains good news isn't a security page.

  • SOC 2 Type II — formal audit planned; controls are being built to that standard from the start.
  • Customer-managed single sign-on (Microsoft Entra ID, Google Workspace) for chamber staff accounts.
  • Signed webhooks for outbound event delivery.
  • Configurable data-retention windows per chamber.
Security FAQ

The questions procurement asks.

Need a full security questionnaire completed? Email hello@chamberzu.com and we'll turn it around.

Where is our data hosted?

In the United States, on AWS infrastructure. If your chamber has a specific residency requirement, talk to us before you sign anything.

Are you SOC 2 certified?

Not yet. We are building to SOC 2 controls and intend to complete a Type II audit, but we will not claim a certification we do not hold. We are happy to complete a security questionnaire in the meantime.

Do you sign a DPA or BAA?

We will sign a data processing agreement. We do not handle protected health information, so a BAA is not applicable to how chambers use Chamberzu.

Who at Chamberzu can see our member data?

Only engineers with a specific operational need, using multi-factor authenticated, logged access. Support cannot browse your members casually, and nobody is reading your data for analytics.

What happens to our data if Chamberzu goes away?

You can export everything at any time, so you are never dependent on us being reachable. We would give customers notice and a full export well ahead of any wind-down.

Can we restrict what our own staff and volunteers can see?

Yes. Roles cover membership, events, finance, and read-only access, so a committee volunteer can run their program without seeing member financials.

Responsible disclosure

Found something we should know about?

Email security reports to our team and we'll acknowledge within two business days. We don't pursue researchers who report in good faith.

Reports go to a human, not a ticket queue. Please give us reasonable time to fix an issue before disclosing it.