Security

Last updated 26 August 2026

Associations trust MyMember with their members' personal information. This page sets out the measures that protect it.

Workspace isolation

Every organisation's records live in an isolated workspace. Each record carries its organisation's identifier, every query is scoped to a single organisation at the application layer, and the database enforces that boundary with constraints and indexes.

There is no interface, for any role, that reaches across organisations.

Encryption

All traffic to the platform is encrypted in transit using TLS.

Passwords are stored only as salted hashes and cannot be recovered in plain text by anyone, including us.

Sensitive stored credentials, such as integration keys, are encrypted at rest.

Access control

Access is role-based. Administrators grant only the permissions a role requires.

Sign-in supports one-time passcodes as well as passwords.

Access to production infrastructure is limited to named personnel, and administrative actions are written to an audit trail that records who did what and when.

Payments

Card details are never transmitted to or stored on our servers. Payments are handled by a PCI-DSS compliant payment provider, and we retain only the transaction reference and status.

Backups and continuity

Databases are backed up on a regular schedule and backups are protected to the same standard as live data.

Restore procedures are tested so that a recovery works when it is needed rather than the first time it is needed.

Reporting a vulnerability

If you believe you have found a security issue, write to [email protected] with "Security" in the subject line and enough detail to reproduce it.

Please give us a reasonable opportunity to fix the issue before disclosing it publicly. We will acknowledge your report within two working days and keep you updated.

Please do not run automated scanners, denial-of-service tests, or any test that could affect other organisations' data.

Incident notification

If a breach affects your data we will notify affected administrators and the relevant authority without undue delay, describing what happened, what data was involved and what we are doing about it.

Still have a question?

Write to [email protected] or call +91 90991 88261.