Security and data protection
Protecting your club’s data is at the heart of everything we build. Discover the measures and protocols we implement to ensure the confidentiality, integrity, and availability of your information.
Security approach
An ISMS structured around international information security standards
Alojamento seguro
EU data centers operated by IONOS SARL
GDPR compliant
Full compliance with European data protection regulations
Secure payments
Powered by Stripe, PCI-DSS Level 1 certified
Alojamento seguro na UE
All your data is hosted by IONOS SARL, located in Sarreguemines, France, within European Union data centers. This guarantees that your information never leaves European jurisdiction.
Encryption in transit
All communications between your browser and our servers are protected by TLS (HTTPS) encryption, ensuring that no third party can intercept your data in transit.
Encryption at rest
Sensitive data stored in our databases benefits from encryption at rest, adding an additional layer of protection against unauthorized physical or logical access.
Automated backups
Automated daily backups with a rolling 90-day retention period ensure your data can be recovered in any situation. Backup integrity is regularly tested.
Data separation
Each club’s data is logically isolated within our infrastructure, preventing any cross-access between organizations and ensuring strict confidentiality.
Exclusão controlada
No encerramento da sua conta, os seus dados pessoais são eliminados ou anonimizados de forma irreversível, nos prazos e de acordo com as exceções legais detalhadas na nossa política de privacidade.
Role-Based Access Control (RBAC)
We implement a granular permission system that ensures each user only accesses the data and features corresponding to their role within the club. Permissions are configurable by administrators.
Principle of least privilege
By default, users receive only the minimum permissions strictly necessary for their function. This approach minimizes the attack surface and limits the impact of any potential compromise.
Secure authentication
Passwords are hashed using modern algorithms. Two-factor authentication (2FA) is available to add an extra layer of protection. Sessions are managed securely with automatic expiration mechanisms.
Administrative audit trail
All sensitive actions such as role changes, data deletions, access modifications, and configuration changes are logged with full traceability, enabling thorough security reviews when needed.
Session management
User sessions are protected against hijacking and fixation attacks. Automatic timeouts ensure that inactive sessions are terminated, reducing exposure to unauthorized access.
Invitation-based access
Access to club spaces is controlled through a secure invitation system. No one can join a club environment without explicit authorization from an administrator.
OWASP Top 10 protection
Our development practices systematically integrate protection against the main application vulnerabilities identified by OWASP: XSS, CSRF, SQL injection, IDOR, and more.
Penetration testing
We conduct regular security testing to proactively identify and fix vulnerabilities before they can be exploited, ensuring our platform stays ahead of emerging threats.
Dependency management
All third-party dependencies are regularly audited through automated tools to detect and patch known vulnerabilities, keeping our software supply chain secure.
Code review
Every code change undergoes systematic peer review before being deployed to production, ensuring quality, consistency, and the absence of security regressions.
Secure development lifecycle
Security is integrated at every stage of our development process, from design and architecture decisions to testing and deployment, following industry best practices.
Monitoring and alerting
Our systems are continuously monitored for unusual activity, performance anomalies, and potential security threats, with automated alerting to enable rapid response.
Centralized account management
We use a centralized account management system that streamlines control and monitoring of user access to enhance security across all our internal systems.
Password management
We maintain the integrity and security of login credentials through a robust password management system. Two-factor authentication (2FA) is mandatory for all accounts, adding an essential layer of protection against unauthorized access.
Principle of least privilege
Access privileges are carefully managed according to the principle of least privilege. Users only receive the minimum level of access required to perform their tasks, minimizing potential security risks.
Security watch
We maintain a continuous watch on vulnerabilities, emerging threats and security best practices to proactively adapt our defenses and keep the platform up to date.
Awareness and training
Security awareness is an ongoing commitment. Regular training, participation in professional security communities, and continuous self-education ensure that security decisions are always informed by the latest standards and threats.
Incident management
A documented procedure enables us to detect, respond to, and communicate about security incidents swiftly and transparently, ensuring continuous improvement of our defenses.
Our approach
Information Security Management System (ISMS)
Clubify has implemented an Information Security Management System (ISMS) structured around internationally recognized information security standards. This methodical framework shapes our entire approach to protecting your data.
Our ISMS is built on formal risk assessment, proportionate safeguards, and continuous improvement, providing a structured and rigorous approach to information security.
- Formal identification and assessment of risks to user data
- Proportionate technical and organizational measures
- Continuous monitoring, auditing and improvement of our security practices
- Documented policies, procedures and controls
Management statement
Clubify’s management is committed to an information security approach aimed at ensuring the confidentiality, integrity, and availability of information entrusted by its users.
This commitment is reflected in the implementation of an ISMS structured around internationally recognized information security standards, together with a process of continuous improvement of our security posture.
Adequate resources are allocated to maintain and improve our security level, and all team members are made aware of their responsibility in protecting information.
Evan Petit, founder & president of Clubify
Questions about our security?
Our team is available to answer any questions about how we protect your data.