Security and data handling

Restricted connections

Connect Stripe using a restricted key with read permissions for subscriptions, invoices, products and prices. The reconciliation connection never creates charges or changes membership permissions. Select the Stripe products that belong to each website. You can remove the saved key or rotate the WordPress connector token from the workspace.

Credential handling

Stripe connection keys are encrypted before database storage, with the encryption key held separately in the application environment. The encrypted value is bound to its website. Connector tokens are stored as hashes by MemberLedger and displayed only when created or replaced. Your WordPress installation stores its copy of the connector token in its options database, so protect WordPress administrators and backups.

Workspace protection

Protected pages require Sign in with ChatGPT. The server checks account ownership on data access, uses prepared database queries, validates uploads and limits requests. Browser changes require same-origin requests. Stripe billing webhooks require a valid signature and are checked for retries. HTTPS protects hosted connections.

Review before action

Findings can reflect incomplete snapshots, custom access rules or intentional subscriptions. Check the source systems before contacting members or changing their accounts. Monitor the last successful check and investigate stale or failed syncs. Export your review history as part of your own operating procedures.

Report a problem

Email support with a description and steps to reproduce. Do not include passwords, complete keys, payment card details or other customers’ records. We have not claimed SOC 2 certification or an independent penetration test.

Contact

Dardan Pasholli, operating MemberLedger in the United States.
dardan201010@gmail.com