Security is an operating disciplineDiscuss your requirements
Security & data integrity

Trust is not a badge.
It is how the system behaves.

Black Sparrow is built around operational controls that protect member boundaries, preserve financial history and make consequential actions accountable.

Current engineering controls

Integrity at the
data-model level.

These controls are implemented in the application today. Formal compliance certification remains a future program and is not claimed here.

01

Server-side member isolation

A member cannot use the API to read another member’s account. Household access is limited to the configured primary relationship.

02

Staff role enforcement

Member, staff, manager and administrative paths are separated, with authorization checks applied on protected endpoints.

03

Immutable POS source rows

Imported source transactions are not rewritten to hide corrections. Adjustments become distinct ledger entries with their own history.

04

Integer-cent money

All application money is stored and calculated as integer cents. Floating-point money paths are intentionally avoided.

05

Idempotent financial jobs

Imports, dues, minimum shortfalls, notifications and statements use unique operational keys so safe retries do not double-post.

06

Audited administrative action

Financial and administrative changes write audit history that can be reviewed in the staff console and reports.

07

Conflict-safe reservations

Database constraints protect tee-time and range capacity from concurrent double-booking, with explicit conflict responses.

08

Revocable digital credentials

Member QR credentials are opaque, revocable and checked against current membership status when scanned or opened.

09

Controlled reconciliation

Stripe and POS activity is reconciled back to the club ledger instead of being treated as a disconnected payment record.

Transparent posture

What we claim.
What we do not.

Implemented now

Role enforcement, member isolation, audit logs, immutable source activity, integer-cent ledger, idempotent jobs, credential revocation and controlled exports.

Scoped per deployment

Backups, hosting topology, retention, email delivery, processor configuration, operational monitoring and access ownership.

Not yet claimed

Black Sparrow does not currently claim SOC 2 or ISO 27001 certification. A formal assurance program belongs on the roadmap as the customer base and enterprise requirements grow.

Your requirements

Bring us the security questionnaire.

We will answer against the actual architecture, identify configuration decisions and separate current controls from roadmap work.

Start the conversation ↗