Security & responsible disclosure

Last updated: 16 August 2026

How access is controlled

Every record in CA Leadership OS is scoped to one organisation and access rules are enforced in the database itself, not only in the interface. Members of one organisation cannot read another organisation's data.

Personal development data is limited to the person and their active developer. Notes marked developer-private are readable only by their author. Anonymous assessment answers are separated from the responding account and reported only as aggregates above the configured minimum group size.

Payments

Card details are entered directly with Stripe and are never received or stored by CA Leadership OS. Incoming payment notifications are signature-verified before any subscription change is applied.

Administrative accountability

Sensitive administrative actions — archiving or restoring a company, role changes, certification decisions, granting access and anonymising a member — are written to an audit record.

Reporting a vulnerability

If you believe you have found a security issue, please report it privately to the operator's security contact before disclosing it publicly: [security contact email, to be completed by the operator]. Please include steps to reproduce and do not access, modify or retain other people's data while testing.