Security
Built like it handles political money. Because it does.
Campaign platforms hold donor identities, giving histories, and payment flows for one of the most targeted sectors online. Here is our posture, plainly.
Payments
Card data never touches our servers
Card entry happens inside Stripe's own secure fields — our systems see a payment token and the last four digits, never a card number. That keeps the platform in PCI's lightest scope (SAQ-A), with a maintained inventory of every code path that talks to Stripe.
Your money, your Stripe account
Funds settle directly to your campaign's own Stripe account. We can't hold, move, or freeze your money — structurally, not just contractually.
No charge without a human
Financial endpoints refuse GET requests and unsigned submissions outright, so an email scanner following links can never trigger a charge. Upsell charges require a signed, single-use, short-lived token plus an explicit confirmation.
Daily reconciliation
An automated job compares our records against Stripe's every day, so drift is caught by a machine — not by your treasurer at filing time.
Access & isolation
Tenant isolation at the database layer
Every table enforces row-level security — one campaign's staff cannot read another campaign's data even if the application layer had a bug. Isolation is a database guarantee, not a query convention.
Mandatory two-factor admin access
Every admin account requires TOTP two-factor authentication. No exceptions, no opt-out — including for us.
CAPTCHA-protected authentication
Sign-in, sign-up, and password-reset are protected by Cloudflare Turnstile, blocking credential-stuffing and email-bombing at the front door.
Role-based team access
Owners, admins, and read-only viewers per campaign — and elevated roles can only be granted by platform staff, so access can't quietly multiply.
Engineering discipline
Defence in depth on donor pages
A strict Content-Security-Policy on every donor-facing page, sanitised rich text at write time, signed and verified webhooks, and rate limiting on all public endpoints.
Data residency and retention
Donation and donor records are stored on infrastructure located in Canada, with automatic pruning of operational logs on fixed retention schedules — data that stops being useful stops being stored.
Audit trail
Sensitive actions — refunds, upsell charges, subscription changes — write an audit record with actor and outcome. When something needs explaining, the trail already exists.
Questions welcome
If your party or association has a security review process, we like those. Send the questionnaire — detailed answers, not marketing answers — to dean@testerdigital.ca.
Ready to raise more?
Your first page can be live this week. We onboard campaigns one at a time so launches stay clean — if you've got a race coming up, let's talk timelines.