Skip to main content

Security & trust

Your data is not in a table with everyone else's

Most platforms in this market put every customer in one shared database and separate them with a column. CommunityForce gives each organization its own database and its own file storage. That difference is the answer to most of what a security review asks about.

A separate environment, not a shared one

Each organization runs in its own private environment: its own database, its own file storage, its own branding, on your own web address. Applicants experience your organization, not a vendor's product.

For a reviewer assessing risk, this collapses a long list of questions into a short one. There is no shared table to be queried across, and no tenant-filter bug that could expose one customer's applicants to another.

Separate database

Your records live in a database of their own, not pooled with other customers'.

Separate file storage

Transcripts, essays and tax documents are stored in your own container.

Your own web address

Your branding and your domain, so applicants never leave your identity.

Microsoft Azure

Managed databases, cloud storage and zero-downtime updates.

Who can see what

Applicant records hold financial information, personal circumstances and documents people would not want read by anyone who did not need to. Access is controlled down to the program.

  • Single sign-on

    Staff and students sign in with their existing institutional account over SAML 2.0, so access follows your directory rather than a second password list.

  • Role-based permissions

    Control what each staff member, reviewer and partner can see and do — including which programs they are allowed to touch at all.

  • Two-factor sign-in

    Optional second factor by email or text, alongside configurable password policies, account lockout and bot protection on public forms.

Controls inside the review itself

Decide which parts of an application each reviewer sees and when, and whether reviewers can see one another's scores. That supports blind and staged review — a defensible process you can describe to a board, not just a claim that one exists.

Evidence, not assurances

An audit does not ask whether you were careful. It asks what happened, when, and who did it.

Activity logging

Structured logging of activity across the platform, to support audit and accountability requirements rather than to be reconstructed after the fact.

Encrypted throughout

Encrypted connections across the platform, with credentials held in a managed cloud secrets vault.

Accessibility

Built to WCAG 2.2 AA. Applicants using a screen reader or a keyboard are applying for the same awards as everyone else, and a form they cannot finish is a program they cannot enter.

Your history, imported

Users, applicants and historical applications come in from spreadsheets through guided templates, so moving platforms does not mean leaving your record behind.

Send us your security questionnaire

We would rather answer it properly than have you guess from a web page.