Security and trust

Built for careful campaign operations.

CampaignOS operates around tenant isolation, guarded publishing, explicit access surfaces, auditability, and human review. Security and resilience work continues as the product grows.

Campaign administrators reviewing access, protected records, and a preview-to-publish checkpoint
Current controlsClear access, protected campaign records, and a deliberate path to public publishing.
  • Tenant-scoped workspaces
  • Preview and publish separation
  • Role-aware access

Current trust posture

Controls that support careful operation today.

The current baseline separates campaign workspaces, access surfaces, preview and publishing, and protected internal tenants.

Tenant boundaries

Campaign workspaces are tenant-scoped, and protected internal tenants are guarded from ordinary cleanup and suspension actions.

Controlled publishing

Preview, publish, and live-site states remain separate so teams can review changes before public release.

Role-aware access

Public, account, tenant, volunteer, and platform-operator surfaces use distinct session and access handling.

Operating boundary

Operational software does not replace professional judgment.

CampaignOS does not certify ballot-access compliance, signer eligibility, petition validity, submission readiness, or official campaign-finance filings.

  • No substitute for qualified election counsel
  • No official paper-petition replacement
  • No official campaign-finance filing production
  • Donation processing remains with configured providers

Start with the proven path

Start with clear operating boundaries.

Create the campaign workspace, then configure only the workflows appropriate for your campaign and jurisdiction.