Security

Security at Randel: what we do and what the evidence covers

A membership platform holds personal data, payment records, signed documents and voting results. This page summarizes how Randel protects them, and links to the documents your board, legal counsel or IT reviewer will want to read.

Precise claims, not broad badges

Randel runs on third-party cloud infrastructure whose provider holds independently assessed security programs, such as ISO/IEC 27001 certification and SOC 1 and SOC 2 reports. That evidence covers the infrastructure layer only; it is not a certification of Randel. On top of it, Randel applies encryption in transit and access controls, regularly audits its own code and infrastructure, and publishes GDPR and LGPD policies.

What you can do with Randel

Infrastructure

Hosted on a cloud provider with ISO/IEC 27001 certification, SOC 1 and SOC 2 reports and PCI DSS validation for its own scope.

Encryption in transit

Data is encrypted in transit, as documented in the Privacy Policy.

Access controls

Permissions and groups limit what admins and members can see and do.

Internal audits

Randel regularly audits its own code and infrastructure, separately from the provider's assessments.

Data ownership

Your organization owns its community data; Randel hosts and operates the platform.

Payments on your Stripe account

Dues and tickets are processed in your own Stripe account; Randel does not hold member funds.

Shared responsibility at a glance

Security in a hosted membership platform is shared between the infrastructure provider, Randel, your organization and Stripe. Knowing who does what makes a security review faster and more accurate.

Party Typically responsible for
Infrastructure provider Data centers, hardware, networking and underlying cloud services
Randel The application, encryption in transit, access controls, internal audits, legal policies and per-client configuration
Your organization Which admins get access, what member data is collected, member notices and data-subject requests
Stripe Processing payments in your own Stripe account

Full security, privacy and compliance guide →

Legal and privacy documents

Randel's safeguards are documented in its legal pages rather than in marketing claims. No method of transmission over the internet or electronic storage is absolutely secure, and Randel does not describe these practices as a guarantee. If your procurement process requires additional documentation, ask us during the demo.

Privacy Policy → GDPR information → Organization terms → Implementation, data ownership and support →

Frequently asked questions

Is Randel ISO 27001 or SOC 2 certified?

No, and we do not claim to be. Those certifications and reports belong to the infrastructure provider and cover the hosting layer. Randel's own safeguards, such as encryption in transit, access controls and internal audits, are documented in our legal pages.

Who owns our member data?

Your organization does. Randel hosts and operates the platform and processes member data on your behalf to provide the service, as described in the Organization Terms.

Does Randel comply with GDPR and LGPD?

Randel publishes GDPR and LGPD policies, customized per client against a documented baseline. Compliance also depends on your role as the organization that decides what member data to collect, so review the legal pages with your counsel.

How are member payments handled?

Dues and tickets are processed by Stripe in your organization's own Stripe account. Your organization is the merchant and keeps its PCI DSS responsibilities as a merchant, as explained in the security guide.

See Randel with your own workflows

Book a demo and we usually follow up within one business day.