We take the privacy of the people and organizations who use J-Opps seriously. Here's how we approach it.
Sign-in is handled by a dedicated authentication service. We never see or store your password in readable form.
Access to data is restricted by rules enforced in the database itself, not just in the app. Individuals can only see their own applications and RSVPs, and organizations can only see the people who responded to their own opportunities. Exact event addresses are limited to people who have RSVPed or applied, and to the organization.
New organizations are reviewed by an administrator before their opportunities appear publicly. Reports from the community are handled through a moderation queue, and administrator actions are recorded in an audit log.
Sign-up and sensitive forms use bot protection, and repeated sign-up attempts are rate limited.
If you believe you've found a security problem, please tell us right away using the Feedback button in the header, and avoid sharing the details publicly until we've had a chance to respond.