Security & privacy

Randel security, privacy and compliance: what applies to whom

Randel runs on third-party cloud infrastructure whose infrastructure provider maintains independently assessed security programs, such as ISO/IEC 27001 certification and SOC 1 and SOC 2 attestation reports. That evidence covers the infrastructure layer only and is not a certification of Randel itself. On top of it, Randel applies encryption in transit and access controls, regularly audits its own code and infrastructure, and publishes GDPR and LGPD policies that are customized per client against a documented baseline.

By the Randel team · Last reviewed September 27, 2026

At a glance

  • Infrastructure provider: ISO/IEC 27001 certification, SOC 1 and SOC 2 reports, PCI DSS validation
  • Provider controls mapped to NIST SP 800-53 and the HITRUST CSF
  • Infrastructure evidence covers the hosting layer, not Randel as a company
  • Randel: encryption in transit, access controls and regular internal audits
  • Legal policies cover GDPR (EEA and UK) and LGPD (Brazil), customized per client
  • No method of transmission or storage is absolutely secure

Why a security review should separate each layer

A membership platform holds personal information, payment-related records, signed documents and sometimes voting results. That makes security part of the buying decision, not an afterthought. The most useful reviews separate four layers: the infrastructure provider that runs the data centers, the platform vendor that builds and operates the application, the payment processor, and the client organization that decides what data to collect and who can see it.

Precision matters because the evidence available at each layer is different. A certificate earned by a cloud provider says a lot about its data centers and very little about the software running on top of them. Reading each item for what it is helps your board, legal counsel or IT reviewer ask the right follow-up questions.

how Randel handles implementation and data ownership →

Infrastructure security evidence, described precisely

The infrastructure provider behind Randel maintains several independently assessed security programs. They are not interchangeable certifications: some are certificates, some are auditor reports, and some are frameworks used to organize controls.

  • All six items describe the infrastructure provider, not Randel's application, processes or staff
  • Each item has its own scope and date, so the scope matters as much as the name
  • Randel does not claim any of these certifications, reports or validations for itself
Item Type of evidence Who issues or assesses it What it tells you
ISO/IEC 27001 Certification An accredited certification body audits against the standard published by ISO and IEC The provider runs an information security management system that met the standard for a defined scope when audited
SOC 1 report Attestation report An independent CPA firm, under AICPA attestation standards How controls relevant to customers' financial reporting are designed and, in a Type 2 report, how they operated over a period
SOC 2 report Attestation report An independent CPA firm, using the AICPA Trust Services Criteria How controls for security and, where in scope, availability, processing integrity, confidentiality and privacy are designed and operating
PCI DSS Compliance validation A Qualified Security Assessor or a self-assessment, following PCI Security Standards Council rules The provider's in-scope environment met the requirements for protecting cardholder data when validated
NIST SP 800-53 Control framework Published by the U.S. National Institute of Standards and Technology; there is no NIST certificate The provider maps its controls to a widely used catalog of security and privacy controls
HITRUST CSF Certifiable framework Maintained by HITRUST; assessments use HITRUST-authorized external assessors The provider maps its controls to a framework that combines requirements from several standards; certification is a separate outcome with its own scope

What Randel does on top of the infrastructure

Randel's own safeguards sit at the application and operations layer. They are documented in Randel's legal pages rather than in third-party certificates, so you can read them directly.

No method of transmission over the internet or electronic storage is absolutely secure, and Randel does not describe these practices as a guarantee.

  • Encryption in transit and access controls, as documented in the Privacy Policy
  • Regular internal audits of Randel's code and infrastructure, separate from the infrastructure provider's assessments
  • Legal policies covering GDPR for users in the EEA and UK and LGPD for users in Brazil
  • Client-specific policy adjustments made against a documented baseline, so policies reflect each community's real data flows
  • The client owns its community data; Randel hosts and operates the platform

Randel Privacy Policy →

Shared responsibility: who secures what

Security in a hosted membership platform is shared. The table below shows how responsibilities typically divide when a community runs on Randel.

Payments deserve special attention. Dues and tickets are processed in the organization's own Stripe account, so the organization is the merchant. The PCI Security Standards Council explains that merchants who outsource payment processing still have PCI DSS responsibilities, such as confirming their providers protect cardholder data.

Party Typically responsible for What to confirm
Infrastructure provider Physical data centers, hardware, networking and the underlying cloud services The scope and date of its certifications and attestation reports
Randel The platform application, encryption in transit, access controls, internal code and infrastructure audits, legal policies and per-client configuration How controls and policies apply to your configuration
Client organization Which admins get access, what member data is collected, member notices and data-subject requests for data it controls Internal roles, admin permissions and privacy notices
Stripe Processing payments in the organization's own Stripe account Your Stripe account settings and the payment obligations that stay with you as the merchant

how membership payments run on your own Stripe account →

GDPR and LGPD: roles depend on the processing relationship

Privacy compliance is not a checkbox attached to a software product. Under the GDPR, a controller determines the purposes and means of processing and a processor handles personal data on the controller's behalf. Brazil's LGPD uses similar roles, and the ANPD guide on processing agents explains how to identify the controller, the operator and the data protection officer in practice.

Randel's Organization Terms describe the organization as determining the purposes and means of processing member data, with G2F, the company behind Randel, processing that data on its behalf to provide the service. G2F documents how it processes personal data in its Privacy Policy and GDPR information page. Client organizations remain responsible for member notices and for responding to data-subject requests relating to data they control.

GDPR information for Randel users →

Security questions to ask any membership software vendor

Use these questions with every vendor on your shortlist, including Randel. Treat the answers as evidence to verify, and ask for documents where your procurement process requires them.

  • Who is the infrastructure provider, and what are the scope and dates of its certifications and reports?
  • How is data encrypted in transit, and how are admin access and permissions controlled?
  • What authentication options exist for admins and members?
  • How often does the vendor test or audit its own code and infrastructure?
  • How are security incidents handled, and how will you be notified?
  • How are backups made, and how is data restored?
  • Who owns the data, how can you export it and what happens to it when you leave?
  • Which subprocessors handle hosting, payments and email?
  • Which privacy documents apply, and can they be adjusted to your legal context?
  • How are payment responsibilities split between you, the vendor and the payment processor?

the full membership software buyer's guide → start a security conversation with the Randel team →

Related questions

Is Randel itself ISO 27001 certified?

No. The ISO/IEC 27001 certification belongs to the infrastructure provider and covers its infrastructure, not Randel as a company. Randel's own safeguards are its internal code and infrastructure audits, encryption in transit, access controls and documented legal policies.

Is a SOC 2 report the same as a certification?

No. A SOC 2 report is an attestation: an independent CPA firm gives an opinion on how controls are designed and, for a Type 2 report, how they operated over a period. There is no pass or fail certificate, so reviewers read the report's scope, period and any exceptions.

Does running payments on Stripe make our organization PCI compliant?

Not automatically. Outsourcing processing reduces what you handle, but the PCI Security Standards Council notes that merchants keep responsibilities. Confirm with Stripe and your acquirer which validation applies to your organization.

How are policies customized for each client?

Randel maintains a baseline privacy and legal policy. Client-specific adjustments are made on top of that baseline so the documents reflect the actual data flows and legal context of each community.

Want to see Randel for your community?

Book a demo and we usually follow up within one business day.

Book a demo