Security and privacy

How Carabiner handles your families' data.

What is true today, stated plainly, and what we plan to earn. We do not hold any security certification yet and this page will not say we do until an auditor signs.

True today.

  • Row-level security on every table. The database is Postgres, hosted on Supabase, and access rules are enforced in the database itself, not only in the app. A den leader manages only their own den. A parent sees only their own household's records, plus the names and roles of the pack's leaders. These rules are covered by automated tests that run on every change.
  • Magic-link sign-in. A link sent to your email, no password to store, reuse, or leak.
  • No youth accounts. Kids never sign in. No youth logins, no youth photos, no youth contact details, and no adult-to-youth channel of any kind.
  • The minimum about a kid. Name, den, rank, member ID, and an optional birth date for rank eligibility. Household adults hold the contact details.
  • Youth names never in source control. Real rosters are data, loaded into the database; they are never committed to the code repository.
  • No payment data held. Carabiner takes no payments today. When collections ship, cards will be handled by the payment processor, not stored by us.
  • Every grant is audited. Advancement changes record who made them and from which session, and cannot be quietly rewritten after export.
  • Export or delete on request. A household's data is exported or removed when a guardian asks. eric@extima.com

Roadmap.

Planned. None of these is held today.

  • SOC 2 Type II. An independent audit of our security, availability, and confidentiality controls over a period of months, the report councils and chartered organizations will ask for. Planned once the product has run for a full program year.
  • Independent penetration test, annually, with a summary published here.
  • Children's-privacy review with counsel. Carabiner collects nothing from children directly, and we want that reviewed against COPPA and written up as a published children's-privacy statement.
  • Published data-retention and deletion policy, and a list of the services that process data on our behalf.
  • Youth-protection alignment. A written statement of how the no-youth- accounts, no-chat design maps to youth-serving organizations' digital-contact rules, reviewed by people who administer those rules.

Found a security problem? Email eric@extima.com. We will answer, fix it, and say what happened.