The strongest security control this site has is that it holds nothing worth stealing. Here is how it is built, and how to tell us if something is wrong.
Steward-Ship holds no donor data, no constituent records, no payment information, and no user accounts. There is no login, no database of visitors, and no integration with any nonprofit's CRM. The prototypes on this site run entirely in your browser using sample content, and nothing you interact with in them is transmitted to us.
That is a design decision, not an accident. A site that never receives donor information cannot leak it.
The only personal information the site ever receives is what a person voluntarily types into the contact form or the newsletter signup, which is a name and an email address. Both are described in the Privacy Policy.
Steward-Ship is a static site. Pages are pre-built HTML, CSS, and JavaScript files served from Cloudflare's global network. There is no application server to compromise, no database engine, no server-side code execution, and no administrative web interface exposed to the internet.
Content is authored in a private source repository and deployed through an automated build. Changes are versioned, which means any unwanted change can be identified and reverted quickly.
The site depends on a small number of established providers, each of which maintains its own security program and public compliance documentation:
| Provider | Function |
|---|---|
| Cloudflare | Hosting, DNS, TLS, edge security |
| Google Analytics | Aggregate traffic measurement |
| Web3Forms | Contact form relay |
| Kit | Email newsletter delivery |
Providers are reviewed before adoption and removed when they are no longer needed.
If you have found a security issue on steward-ship.com, we want to hear about it and we will take it seriously.
Email hello@steward-ship.com with "Security" in the subject line. Please include the affected URL, a description of the issue, the steps to reproduce it, and what an attacker could do with it. Screenshots or a short proof of concept help.
| Stage | Our commitment |
|---|---|
| Acknowledgment | Within 3 business days |
| Initial assessment | Within 10 business days |
| Fix for a confirmed critical issue | As fast as possible, typically within 7 days |
| Follow-up | You will be told when it is resolved |
Steward-Ship is an independent publication and does not run a paid bug bounty. Credit in a public acknowledgment is offered gladly to anyone who reports responsibly and wants it.
In scope: the steward-ship.com domain and its subdomains, and the content served from them.
Out of scope: the underlying infrastructure of Cloudflare, Google, Web3Forms, or Kit, which should be reported to those companies directly. Also out of scope are findings with no demonstrated security impact, such as missing best-practice headers on a static page, version banners, clickjacking on pages without state-changing actions, and automated scanner output submitted without validation.
When testing, please:
If you make a good faith effort to follow this policy while researching a vulnerability, we will consider your research authorized, will not pursue or support legal action against you for it, and will help make clear to anyone else that your activity was authorized. If a third party brings legal action against you for research conducted in accordance with this policy, we will say so.
This safe harbor applies only to the scope defined above and does not authorize action against our service providers or any other party.
In the event of a security incident affecting information collected through this site, we will investigate promptly, take the site offline if that is what containment requires, and notify affected individuals by email without undue delay and in any case as required by applicable law. Given the categories of information involved, an incident here would concern email addresses and message contents, not donor or financial records.
If your institution's information security office is reviewing this site because a fundraising colleague wants to use an idea from it, the short answer is that Steward-Ship is a publication, not a vendor. It receives no institutional data, has no integration with institutional systems, requires no account, and enters into no data processing relationship. Reading it is closer to reading a trade journal than to procuring software.
If a formal questionnaire is still required, email hello@steward-ship.com and it will be answered honestly and quickly.
Related reading: Privacy Policy, Terms of Service, Cookie Policy.