Account security
Sign-in with Google, Apple or email and password; breached-password screening on sign-up; multi-factor authentication available to all users and required for privileged administrative actions.
Data access
Row-level security policies on every table, least-privilege grants, and a single controlled write path for votes and financial records. Administrative actions are recorded in an audit log with before and after state.
Voting integrity
Server-side enforcement of vote limits, schedule windows and eligibility; database-level uniqueness constraints; rate limiting and bot friction on guest voting; and a fraud review queue with risk scoring.
Payments
Card data is handled entirely by our PCI-compliant payment partner and never touches our servers. Payment events are verified by signed webhooks before any balance is changed.
Reporting a vulnerability
Email legal@voteforcause.com with steps to reproduce. Please do not test against live competitions, access data that is not yours, or run denial-of-service or automated scanning. We will acknowledge reports and will not pursue action against good-faith research that follows these guidelines.