Security

Privacy-first foundations before fundraising workflows.

The app uses encrypted personal fields, lookup hashes, prepared statements, passwordless login, CSRF protection, and tenant-scoped queries.

Encrypted PII at rest

Hashed OTP codes

Session cookies with HttpOnly and SameSite

Read-only enforcement for expired demos