Skip to content

    Security at Connect My Alumni

    · Updated

    Security at Connect My Alumni

    How is each institution’s data kept separate?

    Connect My Alumni is a multi-tenant platform: many institutions share the same software, but every record belongs to exactly one organisation. Separation is enforced inside the database with row-level security (RLS) policies, so a query made on behalf of one institution cannot read another institution’s rows, even if application code had a bug.

    Public pages such as an institution’s microsite read from an explicit allow-list of public columns. Private fields — contact details, verification documents, donation records — are never exposed to anonymous visitors.

    Related: Member and staff management

    Who can see and change alumni records?

    Access is role-based. Institution admins manage settings and data; staff members can be given narrower duties such as reviewing verification requests or managing events; alumni see the directory and content your institution makes available to members.

    Alumni manage their own privacy settings, choosing which profile details are visible to other members. Directory visibility respects those settings.

    • Admin, staff and member roles with different permissions
    • Staff access can be added or removed at any time
    • Per-alumnus privacy and visibility settings
    • Verification queue so unverified sign-ups don’t see member-only data

    Related: Alumni verification workflows · Alumni profiles and privacy

    How do people sign in?

    Alumni and staff can sign in with email and password or with Google or Apple single sign-on, which avoids yet another password and lets the identity provider apply its own protections. Institutions can restrict self-registration to approved email domains.

    Sessions and authentication are handled by a managed authentication service; passwords are never stored in plain text.

    Related: SSO and authentication

    Is data encrypted?

    All traffic between browsers and the platform is served over HTTPS (TLS). Data is stored in a managed PostgreSQL database with encryption at rest provided by the hosting infrastructure. File uploads are stored in managed object storage with access controlled per organisation.

    What is logged?

    The activity audit trail records significant admin and staff actions — for example imports, exports, verification decisions and settings changes — with who did what and when. This helps institutions investigate mistakes and demonstrate accountability.

    Related: Activity audit trail

    Can we get our data out?

    Yes. Admins can export alumni and other records as CSV at any time, choosing the columns they need. Your institution owns its data; exporting it does not require contacting support.

    Related: CSV import and export

    How do elections stay trustworthy?

    Committee elections support OTP-verified voting so each eligible member votes once, with an election audit log for the committee to review.

    Frequently asked questions

    Can another institution on the platform see our alumni?

    No. Every record belongs to one organisation and database row-level security policies prevent queries made for one institution from reading another institution’s data. Public microsite pages only show fields your institution has chosen to publish.

    Do you support single sign-on?

    Yes. Alumni and staff can sign in with Google or Apple, as well as email and password. Institutions can also limit self-registration to approved email domains so only people with an institutional address can join.

    Where is our data hosted?

    Data is stored in a managed PostgreSQL database and object storage operated by our infrastructure provider. If your institution needs a specific hosting region or a data processing agreement, contact us and we will share the current details in writing.

    How do we report a security issue?

    Email hello@connectmyalumni.com with the subject “Security” and as much detail as you can. Please do not publicly disclose the issue until we have had a chance to investigate and fix it.

    Put this into practice

    Start on the free plan, or book a walkthrough with your own alumni data.