Security

Built like it handles political money. Because it does.

Campaign platforms hold donor identities, giving histories, and payment flows for one of the most targeted sectors online. Here is our posture, plainly.

Payments

Card data never touches our servers

Card entry happens inside Stripe's own secure fields — our systems see a payment token and the last four digits, never a card number. That keeps the platform in PCI's lightest scope (SAQ-A), with a maintained inventory of every code path that talks to Stripe.

Your money, your Stripe account

Funds settle directly to your campaign's own Stripe account. We can't hold, move, or freeze your money — structurally, not just contractually.

No charge without a human

Financial endpoints refuse GET requests and unsigned submissions outright, so an email scanner following links can never trigger a charge. Upsell charges require a signed, single-use, short-lived token plus an explicit confirmation.

Daily reconciliation

An automated job compares our records against Stripe's every day, so drift is caught by a machine — not by your treasurer at filing time.

Access & isolation

Tenant isolation at the database layer

Every table enforces row-level security — one campaign's staff cannot read another campaign's data even if the application layer had a bug. Isolation is a database guarantee, not a query convention.

Mandatory two-factor admin access

Every admin account requires TOTP two-factor authentication. No exceptions, no opt-out — including for us.

CAPTCHA-protected authentication

Sign-in, sign-up, and password-reset are protected by Cloudflare Turnstile, blocking credential-stuffing and email-bombing at the front door.

Role-based team access

Owners, admins, and read-only viewers per campaign — and elevated roles can only be granted by platform staff, so access can't quietly multiply.

Engineering discipline

Defence in depth on donor pages

A strict Content-Security-Policy on every donor-facing page, sanitised rich text at write time, signed and verified webhooks, and rate limiting on all public endpoints.

Data residency and retention

Donation and donor records are stored on infrastructure located in Canada, with automatic pruning of operational logs on fixed retention schedules — data that stops being useful stops being stored.

Audit trail

Sensitive actions — refunds, upsell charges, subscription changes — write an audit record with actor and outcome. When something needs explaining, the trail already exists.

Questions welcome

If your party or association has a security review process, we like those. Send the questionnaire — detailed answers, not marketing answers — to dean@testerdigital.ca.

Ready to raise more?

Your first page can be live this week. We onboard campaigns one at a time so launches stay clean — if you've got a race coming up, let's talk timelines.