Signup Crew policy information
Security Statement
Signup Crew’s current security posture and reporting guidance.
Our approach
Just Walking Ventures, LLC, doing business as Signup Crew, uses technical and administrative safeguards intended to protect customer, account, Volunteer, and RSVP information. Security is an ongoing practice, and no online service can guarantee complete security.
This statement describes controls currently implemented in Signup Crew. It does not create a guarantee, service-level agreement, certification, or warranty.
The statement applies, as relevant, across the Signup Crew Service. This includes public Volunteer and RSVP/Event experiences that intentionally do not require an account, authenticated organizer and organization-administration experiences, and platform/Super Administrator experiences. A safeguard applies to the surfaces and actions for which it is designed; authentication controls, for example, do not imply that public registration requires an account.
Connection and hosting security
Signup Crew is delivered over HTTPS/TLS. Vercel provides application hosting, content delivery, functions, and related operational infrastructure. Signup Crew maintains separate Development and Production environments and scopes provider configuration and credentials to the intended environment.
Authentication and sessions
Supabase provides authentication and session management for Signup Crew. Supported account access includes email/password authentication and optional Google authentication. Password credentials are handled through Supabase authentication, and Signup Crew's application database does not store plaintext passwords.
Super Administrator access requires time-based one-time-password (TOTP) multi-factor authentication and the corresponding higher-assurance authenticated session. This requirement applies to Signup Crew's platform-level Super Administrator role. Mandatory MFA is not currently required for every customer account.
Authorization and organization boundaries
Signup Crew separates authentication from authorization. A signed-in identity must also have an active, authorized organization membership or exact Event assignment for the requested operation.
Implemented controls include:
- organization-scoped authorization checks;
- database Row Level Security and restricted database operations where applicable;
- role and plan-entitlement enforcement;
- more limited authority for consequential Owner and Super Administrator actions;
- exact-Event assignments for Event-specific roles; and
- server-side revalidation for privileged operations.
Invitations and account activation
Organization and Event access uses scoped invitations. Relevant flows check the invited email address, invitation status, expiration, organization, role, and current authorization state. Invitation credentials and authentication tokens are not intentionally displayed or stored in application logs.
Credentials and provider integrations
Privileged provider credentials are kept in server-side configuration and environment mechanisms and are not intended for browser-delivered code. Signup Crew separates public client configuration from server-only credentials. The current application source does not contain provider secret values.
Stripe and Resend webhook requests are verified using signed raw payloads before trusted processing. Provider identifiers, processing state, and safe failure information may be retained for delivery, reconciliation, security, and audit purposes.
Payment security
Stripe provides hosted Checkout, payment processing, subscription billing, and the Customer Portal. Customers enter payment details through Stripe-hosted interfaces. Signup Crew does not store full card numbers, CVV security codes, bank-account credentials, or reusable payment credentials.
This statement does not claim that Signup Crew itself has obtained PCI or any other payment-security certification.
Files and communications
Supabase Storage is used for organization branding, Event images, and supported private communication attachments. Private attachments are subject to organization and Event scoping, server-side validation, and authorized access paths. Resend delivers transactional and organization communications.
Auditability
Signup Crew maintains records for selected security-relevant and consequential operations, including administrative actions, roles and invitations, commercial billing state, organization lifecycle actions, and communication delivery. These records support investigation, reconciliation, and accountability. They are not a guarantee that every application action is logged.
Service providers
Signup Crew relies on established service providers for important parts of the security architecture:
- Supabase — database, authentication, sessions, multi-factor authentication, and file storage;
- Vercel — application hosting, content delivery, functions, and operational infrastructure;
- Stripe — hosted payment and subscription services;
- Resend — email delivery; and
- Google — optional authentication when selected by a user.
Each provider operates its own systems and controls. Signup Crew's use of a provider does not make every provider certification a Signup Crew certification.
Security reports
To report a suspected vulnerability or security concern, email support@signupcrew.com. Include enough detail to help us understand and reproduce the issue, but do not send passwords, authentication tokens, full payment-card information, or participant data that is not necessary to explain the report. Using the subject Security report can help us recognize the message.
Please do not disrupt the Service, access data that is not yours, or use a security report as authorization to test Production systems. Signup Crew does not currently promise a specific response-time SLA. This Security Statement and the act of emailing support do not independently authorize security testing.
Signup Crew's proposed good-faith reporting boundaries are described in the separate draft Vulnerability Disclosure Policy intended for https://signupcrew.com/security/vulnerability-disclosure. That policy is not effective and grants no testing authorization unless and until it is approved and published with a final authorized scope.
If Signup Crew determines that a security incident involving personal information requires notification, Signup Crew will notify affected individuals and/or applicable authorities as required by applicable law. Signup Crew does not promise a universal 24-hour, 72-hour, or other fixed notification deadline, and this statement does not create an unsupported incident-response guarantee.
Limits of this statement
Signup Crew does not claim:
- 100% or absolute security;
- “bank-level” or “military-grade” security;
- SOC 2 certification;
- HIPAA compliance;
- Section 508 certification;
- PCI certification by Signup Crew;
- guaranteed uptime; or
- guaranteed backup, restoration, recovery-time, or recovery-point objectives.
Internal backup and recovery work does not currently support a public promise of a particular Production recovery objective. Formal breach and incident-response commitments, detailed provider-log retention, and public recovery claims remain under review.
Changes to this statement
We may update this statement as the Service and security practices evolve. Material changes will receive notice appropriate to the nature of the change and applicable law. The published effective date and version will identify the statement then in force.
Contact
Just Walking Ventures, LLC, doing business as Signup Crew
Security and vulnerability reports: support@signupcrew.com
