Security and trust

Campaign infrastructure should make its boundaries visible.

CampaignOS operates around tenant isolation, guarded publishing, explicit access surfaces, auditability, and human review. Broader successor-platform security and resilience remain active requirements.

Current controls

AT A GLANCE

  • Tenant-scoped workspaces
  • Preview and publish separation
  • Role-aware access

Current trust posture

Controls that support careful operation today.

The current baseline separates campaign workspaces, access surfaces, preview and publishing, and protected internal tenants.

Tenant boundaries

Campaign workspaces are tenant-scoped, and protected internal tenants are guarded from ordinary cleanup and suspension actions.

Controlled publishing

Preview, publish, and live-site states remain separate so teams can review changes before public release.

Role-aware access

Public, account, tenant, volunteer, and platform-operator surfaces use distinct session and access handling.

Operating boundary

Operational software does not replace professional judgment.

CampaignOS does not certify ballot-access compliance, signer eligibility, petition validity, submission readiness, or official campaign-finance filings.

  • No substitute for qualified election counsel
  • No official paper-petition replacement
  • No official TEC or FEC filing production
  • Donation processing remains with configured providers

Start with the proven path

Start with clear operating boundaries.

Create the campaign workspace, then configure only the workflows appropriate for your campaign and jurisdiction.