Every control below is shipped and checkable today, with one exception marked in review: an exportable audit log, full data export, encrypted backups, signed webhooks, a public status page and a published VPAT. No roadmap items on this page.
Built and in final review before release: multi-factor authentication can be required for every account in your chamber, not merely offered. Each person enrols an authenticator app and is issued single-use recovery codes.
Add staff, set their role, and deactivate an account the day someone leaves. Deactivation is immediate and reversible, so an offboarding never means deleting a person's history.
Every account can see its own sign-in history and end every other session in one action, which is what you actually want at the moment a laptop goes missing.
Passwords are hashed and never stored in the clear. Credentials and integration tokens are encrypted at rest, and every connection to the platform runs over TLS.
Administrative actions are recorded in a per-chamber audit log your admins can read and export to CSV. It leaves the platform in a format a board, an auditor or a spreadsheet can take.
Every response carries its own request ID. When you ask us about one screen at one moment, that identifier is how the answer gets found instead of reconstructed.
Tenant isolation fails closed at the framework layer, so a chamber's data is scoped by default rather than by a check someone could forget.
A complete export of your chamber's data is available on every plan, at no charge, without asking us first. Nothing about leaving requires our cooperation.
Database snapshots run hourly and file archives every four hours. Both are encrypted, full-image server backups are held offsite as well, and restores are tested rather than assumed to work.
Section 7 of the terms is the commitment that survives us. Read it in full at section 7.
On insolvency, on discontinuing the product, or on an acquisition where "the buyer does not assume our obligations under these terms", we give "at least 90 days written notice, and the service keeps running normally throughout that period". Within 30 days of that notice, at no charge, we deliver "a complete database dump of your tenant, documented schema, and your uploaded files, in a form a successor can load", provide reasonable assistance to whoever is taking over, and your rate survives an acquisition.
Checks run continuously against the platform with automatic alerting the moment anything degrades. Current status, uptime and the incident history are public at /status, including a machine-readable health endpoint.
We investigate immediately on detecting any suspected incident. If we confirm that chamber or member data was affected, we notify every affected chamber by email within 72 hours of that confirmation, with what happened, what data was involved, what we did about it, and what we recommend you do next. We cooperate fully with applicable notification laws.
A web application firewall and continuous malware scanning run at the host, the server follows an automatic patching cadence, and access is limited to named individuals over key-based SSH only.
Each key carries its own permissions, chosen per resource and separately for reading and writing, with billing as its own permission. A key with no permissions can do nothing.
Outbound webhooks are HMAC-signed with automatic retry, so a receiving system can prove a payload came from us. Zapier covers the automations that do not justify code.
Stripe, Elavon, Authorize.net, PayPal, and for the Philippines Maya and PayMongo, connected to your own account, with funds landing directly with you. Every processor is used through its hosted payment fields, so card data never rests with us.
Every chamber sets its own timezone, and event times are the chamber's own wall clock rather than a translation of ours.
Dues, invoices and event pricing run in your currency, with the formatting and decimal handling that currency actually uses.
Each chamber gets its own website on its own custom domain, included on every plan, updating itself from the CRM.
Built for chambers anywhere. Chambers worldwide โ
A VPAT covering Section 508 and WCAG 2.2 AA is published, not promised. Read the conformance report.
The accessibility statement sets out what conforms today and what is known not to, in plain terms. Read the statement.
Rates are on the site by chamber size, so there is no quote to chase and no RFP needed to learn the number. See pricing.
MFA is built and in final review before release. Once released it can be required for every account in your chamber, not just offered. Each person enrols an authenticator app and is issued single-use recovery codes, so losing a phone is a recoverable event rather than a support ticket that ends in a password reset.
Yes. Administrative actions are recorded in a per-chamber audit log that chamber admins can read and export to CSV. Every response also carries a request ID, so a specific screen at a specific moment can be traced when you ask us about it.
Section 7 of the terms is a continuity clause. On insolvency, discontinuation, or an acquisition where the buyer does not assume our obligations, we give at least 90 days written notice with the service running normally throughout, and within 30 days of that notice we deliver a complete database dump of your tenant, documented schema, and your uploaded files, at no charge. You can also export everything yourself at any time without asking us. Read section 7 โ
Not with us. You bring your own payment gateway (Stripe, Elavon, Authorize.net, PayPal, or for the Philippines Maya and PayMongo) and funds land in your account. Every processor is used through its hosted payment fields, so card details are entered directly into the processor and never reach our servers.
Both. There is a published VPAT covering Section 508 and WCAG 2.2 AA, and pricing is published on the site by chamber size. Because the price is public there is nothing for an RFP to discover, which is usually the slowest part of a procurement.
Security questions belong before a signature, not after. Send the list and you get a written answer, same business day, from the person who built the thing.
Or write straight to contact@champlinenterprises.com, the same inbox that handles every other platform question.