RebelCore Security

Security designed
for the data that
matters most.

Organizations serving youth, families, donors, and vulnerable populations hold sensitive information. RebelCore is the security layer that powers RebelClub — with controls designed to protect that information responsibly.

What we will and won't claim about security

What we describe on this page

  • The security controls built into RebelCore
  • How access and permissions work
  • How audit logging functions
  • How data is handled and isolated

What we do NOT claim

  • SOC 2 certification (not verified)
  • ISO 27001 certification (not verified)
  • HIPAA, FERPA, COPPA, PCI or FedRAMP status
  • Uptime or availability percentages
  • Breach-proof or zero-risk claims
Verified certifications or compliance attestations will be listed here when formally completed. We do not list them before that.

RebelCore security control areas

Six categories of security controls built into the RebelCore platform layer that underlies every RebelClub deployment.
Identity & Authentication

Know who is accessing your system

  • Role-based user accounts
  • Strong password requirements
  • Session management and timeout
  • Multi-factor authentication support
  • Login audit history
Access Control

Limit what people can see and do

  • Granular role permissions
  • Module-level access control
  • Record-level visibility rules
  • Read-only vs write access separation
  • Administrative privilege separation
Data Encryption

Protect data in transit and at rest

  • Encrypted data transmission (TLS)
  • Encrypted data storage
  • Secure credential handling
  • Encrypted backup storage
Audit & Accountability

Know what happened and when

  • User action logging
  • Record change history
  • Login and session events
  • Administrative action logs
  • Tamper-evident audit trail
Tenant Isolation

Your data stays yours

  • Logical data separation per organization
  • No cross-organization data access
  • Organization-scoped permissions
  • Isolated configuration per tenant
Data Protection

Responsible handling of sensitive information

  • Youth and minor data handling practices
  • Sensitive field access controls
  • Data retention policies
  • Right-to-access support

Not everyone needs to see everything.

RebelCore’s role-based access model ensures staff see the information relevant to their responsibilities — and nothing more. Organizations configure roles during implementation to match their actual structure.
Illustrated access levels are examples. Each organization’s permissions are configured individually during implementation.
Custom rolesModule-level accessRead-only configurationsMulti-site scope control
Role-Based Access
ExecutiveFull organization visibility
DevelopmentDonor & fundraising data
Membership StaffMember & program data
Program StaffProgram & attendance data
MarketingAudience & campaign data
Front DeskCheck-in & basic records
Permissions are configured per organization. Access shown is illustrative.

A record of what happened, and when.

RebelCore maintains audit logs of user actions — record changes, logins, administrative actions, and key system events. This supports accountability, incident review, and compliance documentation.
Record changesWho changed what, and when
Authentication eventsLogin, logout, failed attempts
Administrative actionsPermission changes, user management
Incident submissionsForm completion and follow-up events
Audit Log — Anonymized Example
Member record updatedStaff User
Donor opportunity createdDevelopment Lead
Login — successfulAdmin User
Incident report submittedProgram Staff
User permission updatedSystem Admin

Certifications & compliance

RebelClub takes security compliance seriously. We do not list certifications that have not been formally completed. The following represent our active or in-progress compliance work.
[VERIFIED CERTIFICATION]To be published when formally completed
[VERIFIED CERTIFICATION]To be published when formally completed
[VERIFIED CERTIFICATION]To be published when formally completed
[VERIFIED CERTIFICATION]To be published when formally completed
If security certifications or compliance documentation are required for your evaluation, contact your RebelClub representative directly.

Youth and minor data handling

Many of the organizations RebelClub serves work with youth and minors. RebelCore includes specific controls around access to minor records, parental and guardian relationships, and sensitive program data.
🔒

Minor record access control

Access to records involving minors is scoped by role and module

👨‍👩‍👧

Guardian relationship visibility

Guardian and parent relationships are maintained with appropriate access boundaries

📋

Consent management

Communication consent and opt-in tracking for parents and guardians

🛡

Incident confidentiality

Incident records have additional access controls by role and configured permissions

Common Questions

RebelClub does not currently list a verified SOC 2 certification. We will publish certifications when they are formally completed. If this is a requirement for your evaluation, contact your RebelClub representative.
RebelClub does not currently publish a verified HIPAA compliance status. If compliance documentation is required for your evaluation, contact your RebelClub representative directly.
Each organization in RebelClub operates as a separate tenant with logically isolated data. No user can access data from another organization through normal platform operation.
Organizations configure their own role-based access permissions during implementation and can adjust them afterward through the administrator role. RebelClub’s support team can assist with configuration.
Yes. RebelCore includes encryption of data in transit using TLS and encryption of data at rest. Specific implementation details are available to organizations with a data security review requirement.
Yes. Organizations can export their data. Specific export formats and scope should be confirmed with your RebelClub representative during the sales and contracting process.
Yes. Data retention policies exist and are applied within the platform. Organizations can also configure data handling practices appropriate to their context during implementation.
Security concerns should be reported to your RebelClub representative or through the support team. Contact information is available through the Support page and your implementation materials.

Have specific security questions
for your evaluation?