Home · Security & PCI
Terms of Service · Privacy Policy · Security & PCI · Accessibility · Sub-processors · Data Processing Addendum · Copyright Policy
Security & PCI Posture
This page summarizes how Commonwell protects data and handles payment-card scope. It is intended for prospective customers and security reviewers.
Payments and PCI DSS
- All card and bank-account data is collected and processed by a PCI DSS Level 1 certified payment processor, using its hosted, tokenized flows.
- Commonwell never receives, transmits, or stores full card numbers (PAN), CVV, or full bank account numbers. We store only payment-processor tokens and limited non-sensitive metadata (card brand, last four digits, payout status).
- Because cardholder data is entered through the provider's hosted flow, Commonwell is designed for SAQ A scope (e-commerce, fully outsourced to a validated provider). The applicable questionnaire and final classification depend on the production integration and must be confirmed through the organization's own PCI compliance review and attestation.
Infrastructure
- Runs entirely on a serverless edge platform (compute, database, object storage, key-value, and queues). Data is encrypted in transit (TLS) and at rest by the underlying platform.
- Tenant isolation: every record is scoped to a community id and enforced on every query path; cross-tenant access is rejected.
Authentication & access
- Credentials are hashed with PBKDF2 and a production-required, independent server-side pepper. Optional TOTP two-factor authentication with single-use recovery codes.
- Sessions are httpOnly cookies (signed JWT). API access uses scoped, hashed-at-rest API keys. Optional SAML SSO for enterprise customers.
- Commonwell support acts inside a community only through a support session: started by staff who have two-factor authentication, limited to 30 minutes, and logged request by request. A support session can edit the community's public website (profile, theme, page drafts and inactive forms) and reads only what those screens load. It cannot read member records, documents, maintenance requests, violations, form submissions or financial data.
Operational security
- Structured error monitoring. Error and critical events are deduplicated and emailed to our operations alert inbox, and production readiness fails if no alert destination is configured.
- Audit logging of administrative and security-relevant actions.
- Database Time Travel follows the hosting plan's restorable window (currently 30 days on paid plans and 7 days on free plans). In addition, a logical export of the database and a copy of stored documents are written daily to a separate, private backup bucket and kept for 35 days.
Reporting a vulnerability
Email security@commonwell.app. We acknowledge reports promptly and ask for a reasonable disclosure window. Please do not access data that isn't yours.