AlumDeck

Security & trust

Safe to hand to the next committee.

Committees change every year; the alumni records should not leak when they do. AlumDeck runs on your server, gives each helper only the areas they need, and records who did what. Every control on this page is one you can check yourself, and there is no badge here we have not earned.

Controls you can check

Eight controls, and where to check each one.

  • Two-factor sign-in for admins

    An authenticator app or an emailed code. Eight wrong codes lock the account for 15 minutes, and one line in the .env file makes two-factor compulsory for every admin.

    How it works
  • Permissions by committee area

    Thirteen areas, from registrations to giving. A helper sees only the areas you tick; settings, backups and imports are for full admins, and nobody can promote themselves.

    See the admin panel
  • An audit log kept for a year

    Sign-ins, failed sign-ins, changes to 17 kinds of record, two-factor events and imports, with who, when and from which IP address. Kept 365 days by default, read-only in the admin.

    What it records
  • Admin sessions that end

    Signed out after 60 idle minutes and after 12 hours whatever happens. A session is tied to its browser, renewed every 30 minutes, and a new IP address is logged.

    Session details
  • A custom admin address

    Move the panel off /admin to a word you choose. In the settings screen's own words, it makes the panel harder to find, not harder to break into.

    See the admin panel
  • Nightly backups, restore-tested weekly

    At 02:30 every night: the database, the photos and the private documents, with a checksum per file, kept outside the web root. Every Sunday the newest one is rebuilt in a scratch database and every table is counted.

    How backups work
  • Security headers on every page

    nosniff, frame protection, a referrer policy, a permissions policy, HSTS and a Content-Security-Policy. Check them on the demo with one command.

    Check the headers
  • Consent recorded, not assumed

    Four separate consents at sign-up, each stored with the wording version, the time, the IP address and the browser. Campaigns re-check consent for every recipient as they send.

    How members join

Your server, your data

Your members' data never reaches us.

Everything lives in your own database and your own folders. These are the only calls AlumDeck makes to anyone else, and what each one carries.

Every call AlumDeck makes to anyone else
CallWhat it carriesWhen
Licence check at installThe licence key, the product name and your hostnameOnce, on the first installer screen
Licence status checkThe licence key and your hostnameAbout twice a day, and only when someone uses the admin panel or the member area
Cloudflare TurnstileThe bot-check token and the visitor's IP addressOnly if you add the keys; on the join, contact and sign-in forms
Your mail serverThe emails your site sendsWhenever AlumDeck sends mail, through your SMTP
Upload checkA request to your own siteOnce, at install, to prove uploads are served
Tags you addWhatever GA4, Meta or LinkedIn collectOnly if you add their IDs, and only after a visitor accepts cookies

No member names, emails or records are ever sent to AlumDeck, and there is no vendor login to your site. The public site never depends on our servers: it keeps serving whatever happens to us. Member photos are drawn from your own server too; avatars without a photo are initials drawn locally, not fetched from a third party.

Check it yourself

Test the headers in ten seconds.

Run this against the demo now, or against your own site after you install.

curl -I https://demo.alumdeck.com/

Among the answers you should see:

  • Strict-Transport-Security: max-age=63072000; includeSubDomains, two years of HTTPS only
  • X-Content-Type-Options: nosniff
  • X-Frame-Options: SAMEORIGIN, so no other site can frame yours
  • Referrer-Policy: strict-origin-when-cross-origin
  • Permissions-Policy switching off location, camera and microphone
  • Content-Security-Policy, starting default-src 'self'

The admin panel also answers with X-Robots-Tag: noindex, nofollow, so it stays out of search results.

For your members

Private by default.

  • 10profile fields each member can hide
  • 4separate consents, each recorded
  • 60idle minutes before an admin is signed out
  • 365days the audit log is kept
  • Email and phone start hidden; each member chooses, field by field, what signed-in classmates can see.
  • Every form that writes anything has its own rate limit, from sign-in (8 tries a minute) to uploads.
  • Private documents, contact attachments and import files are served only after checking who is asking.
  • The SMTP password and two-factor secrets are stored encrypted.
  • Spreadsheet exports defuse cells that start like a formula, so a member cannot plant one in a committee laptop.
  • Member passwords are at least 10 characters; the first admin's at least 12.

The gaps, before an IT reviewer finds them

What we do not claim.

Ten things an IT reviewer would ask about, answered before they have to.

  • No SOC 2 or ISO 27001 certificate. Those audit a vendor's own hosting; AlumDeck never holds your data.
  • No independent penetration test yet. Planned: release 2.0
  • Admin two-factor is optional in a fresh install until you switch it on or make it compulsory. Planned: release 1.1
  • No two-factor for members: it is for admins only.
  • The audit log records which fields changed, not their old and new values.
  • No back-up-now or download button: backups are fetched over FTP or SSH. Planned: release 1.1
  • Backups need PHP's exec() function; a host that disables it gets no backups.
  • No off-site copy: backups stay on the same server until you copy them elsewhere.
  • Secure-only session cookies are not forced by default. Planned: release 1.1
  • No published security questionnaire or disclosure policy yet. Planned: release 1.1

Everything else AlumDeck does not do, from payments to languages, is on one page.

Your part of the job

Self-hosting means the server is yours.

Six jobs that keep an AlumDeck site safe, in the order we would do them.

  1. Turn on two-factor for every admin

    Each admin enrols from their own profile. Set REQUIRE_ADMIN_2FA=true in the .env file to make it compulsory.

  2. Give helpers only their areas

    A reunion volunteer needs Events, not Members or Giving. Full admin is for one or two people.

  3. Move the admin address

    Settings, General, Admin area address. Bookmark the new one: the old one stops working at once.

  4. Add the cron line, then watch the Backups page

    Without the cron line there are no backups. The page shows when the last one ran and warns when it is stale.

  5. Copy a backup off the server

    Now and then, download the newest backup folder over FTP and keep it somewhere else.

  6. Keep PHP and AlumDeck up to date

    Your host patches the server; you apply AlumDeck releases, listed on the changelog.

Questions

Asked by IT reviewers.

Does AlumDeck hold a security certification?

No, and we will not show a badge we have not earned. SOC 2 and ISO 27001 certify the way a vendor runs its own hosting. AlumDeck runs on yours, and never holds your members' data, so that audit would say little about your site. An independent penetration test is planned for release 2.0.

Can anyone at AlumDeck see our members' data?

No. There is no vendor account on your site and no copy of your data on our side. The only thing AlumDeck sends us is your licence key and your site's hostname, about twice a day.

Where is our data stored?

In your own MySQL or MariaDB database and your own folders, on the hosting you choose, in the country you choose. Private documents and import files sit outside the public folder and are handed out only after checking who is asking.

Is two-factor sign-in compulsory?

For admins it is available to everyone, by authenticator app or emailed code, and one line in the .env file makes it compulsory for all of them. A fresh install leaves it optional today; release 1.1 is planned to switch it on from the start. Members sign in with an email and a password of at least 10 characters.

What happens to our site if AlumDeck stops trading?

Your public site keeps serving from your own server, and your data stays in your own database, whatever happens to us. You also hold the code: it is ordinary, readable PHP.

How do we report a security problem?

Through the contact form, with the topic set to Technical. A published disclosure policy and a security summary for IT reviewers are planned for release 1.1.

Check the controls yourself.

Sign in to the demo as the admin: two-factor, the audit log, permissions and the backups page are all there.

Sign-in details on the demo pageResets every night