Security built into the platform.
Your members’ data and your brand’s reputation matter. FounderPass is designed with tenant isolation, encryption and safe-by-default integration at its core.
Encryption at rest
Sensitive secrets (such as webhook signing keys) are encrypted at rest with AES-256.
SSO authentication
Members and admins authenticate through a managed identity flow, with role-based access for your team.
Tenant data isolation
Every partner is scoped to its own data. Requests are bound to your partner context. One tenant never sees another’s members or analytics.
Isolated sandbox
Test keys hit a separate twin environment with seeded data, so integration testing never touches live members.
Signed webhooks
Outbound events are signed with a per-endpoint secret and every delivery attempt is logged for inspection.
Resilient rate limiting
Shared, atomic rate limits protect the platform across replicas, with abuse-resistant controls on sensitive endpoints.
Designed to protect every tenant.
- Scoped access: partner keys and tokens only ever reach your own data.
- Origin controls: the embed widget runs only on the domains you allow-list.
- Least exposure: credentials are never embedded in client builds; secrets stay server-side.
- Auditable actions: sensitive admin operations are recorded.
Have a security or compliance question for your procurement process? Get in touch. We’re happy to help.
Questions about security or compliance?
Reach out and we’ll walk your team through how FounderPass protects your programme.