By the Randel team · Last reviewed September 27, 2026
Why a security review should separate each layer
A membership platform holds personal information, payment-related records, signed documents and sometimes voting results. That makes security part of the buying decision, not an afterthought. The most useful reviews separate four layers: the infrastructure provider that runs the data centers, the platform vendor that builds and operates the application, the payment processor, and the client organization that decides what data to collect and who can see it.
Precision matters because the evidence available at each layer is different. A certificate earned by a cloud provider says a lot about its data centers and very little about the software running on top of them. Reading each item for what it is helps your board, legal counsel or IT reviewer ask the right follow-up questions.
how Randel handles implementation and data ownership →
Infrastructure security evidence, described precisely
The infrastructure provider behind Randel maintains several independently assessed security programs. They are not interchangeable certifications: some are certificates, some are auditor reports, and some are frameworks used to organize controls.
-
All six items describe the infrastructure provider, not Randel's application, processes or staff
-
Each item has its own scope and date, so the scope matters as much as the name
-
Randel does not claim any of these certifications, reports or validations for itself
| Item |
Type of evidence |
Who issues or assesses it |
What it tells you |
| ISO/IEC 27001 |
Certification |
An accredited certification body audits against the standard published by ISO and IEC |
The provider runs an information security management system that met the standard for a defined scope when audited |
| SOC 1 report |
Attestation report |
An independent CPA firm, under AICPA attestation standards |
How controls relevant to customers' financial reporting are designed and, in a Type 2 report, how they operated over a period |
| SOC 2 report |
Attestation report |
An independent CPA firm, using the AICPA Trust Services Criteria |
How controls for security and, where in scope, availability, processing integrity, confidentiality and privacy are designed and operating |
| PCI DSS |
Compliance validation |
A Qualified Security Assessor or a self-assessment, following PCI Security Standards Council rules |
The provider's in-scope environment met the requirements for protecting cardholder data when validated |
| NIST SP 800-53 |
Control framework |
Published by the U.S. National Institute of Standards and Technology; there is no NIST certificate |
The provider maps its controls to a widely used catalog of security and privacy controls |
| HITRUST CSF |
Certifiable framework |
Maintained by HITRUST; assessments use HITRUST-authorized external assessors |
The provider maps its controls to a framework that combines requirements from several standards; certification is a separate outcome with its own scope |
What Randel does on top of the infrastructure
Randel's own safeguards sit at the application and operations layer. They are documented in Randel's legal pages rather than in third-party certificates, so you can read them directly.
No method of transmission over the internet or electronic storage is absolutely secure, and Randel does not describe these practices as a guarantee.
-
Encryption in transit and access controls, as documented in the Privacy Policy
-
Regular internal audits of Randel's code and infrastructure, separate from the infrastructure provider's assessments
-
Legal policies covering GDPR for users in the EEA and UK and LGPD for users in Brazil
-
Client-specific policy adjustments made against a documented baseline, so policies reflect each community's real data flows
-
The client owns its community data; Randel hosts and operates the platform
Randel Privacy Policy →
Shared responsibility: who secures what
Security in a hosted membership platform is shared. The table below shows how responsibilities typically divide when a community runs on Randel.
Payments deserve special attention. Dues and tickets are processed in the organization's own Stripe account, so the organization is the merchant. The PCI Security Standards Council explains that merchants who outsource payment processing still have PCI DSS responsibilities, such as confirming their providers protect cardholder data.
| Party |
Typically responsible for |
What to confirm |
| Infrastructure provider |
Physical data centers, hardware, networking and the underlying cloud services |
The scope and date of its certifications and attestation reports |
| Randel |
The platform application, encryption in transit, access controls, internal code and infrastructure audits, legal policies and per-client configuration |
How controls and policies apply to your configuration |
| Client organization |
Which admins get access, what member data is collected, member notices and data-subject requests for data it controls |
Internal roles, admin permissions and privacy notices |
| Stripe |
Processing payments in the organization's own Stripe account |
Your Stripe account settings and the payment obligations that stay with you as the merchant |
how membership payments run on your own Stripe account →
GDPR and LGPD: roles depend on the processing relationship
Privacy compliance is not a checkbox attached to a software product. Under the GDPR, a controller determines the purposes and means of processing and a processor handles personal data on the controller's behalf. Brazil's LGPD uses similar roles, and the ANPD guide on processing agents explains how to identify the controller, the operator and the data protection officer in practice.
Randel's Organization Terms describe the organization as determining the purposes and means of processing member data, with G2F, the company behind Randel, processing that data on its behalf to provide the service. G2F documents how it processes personal data in its Privacy Policy and GDPR information page. Client organizations remain responsible for member notices and for responding to data-subject requests relating to data they control.
GDPR information for Randel users →
Security questions to ask any membership software vendor
Use these questions with every vendor on your shortlist, including Randel. Treat the answers as evidence to verify, and ask for documents where your procurement process requires them.
-
Who is the infrastructure provider, and what are the scope and dates of its certifications and reports?
-
How is data encrypted in transit, and how are admin access and permissions controlled?
-
What authentication options exist for admins and members?
-
How often does the vendor test or audit its own code and infrastructure?
-
How are security incidents handled, and how will you be notified?
-
How are backups made, and how is data restored?
-
Who owns the data, how can you export it and what happens to it when you leave?
-
Which subprocessors handle hosting, payments and email?
-
Which privacy documents apply, and can they be adjusted to your legal context?
-
How are payment responsibilities split between you, the vendor and the payment processor?
the full membership software buyer's guide →
start a security conversation with the Randel team →