Security Statement

Security Statement

The Colorado Pilots Association takes the security of your personal information seriously. As a volunteer-run nonprofit, we follow current industry best practices to protect member data and the integrity of our systems.

This page describes our security posture in general terms. We deliberately don’t publish the specific products, vendors, versions, or configurations that implement these controls β€” naming them would only help attackers. Members with a specific concern, and prospective partners evaluating a vendor relationship, can request a private briefing from the webmaster.

Protecting Your Data

We design every CPA service around three principles: confidentiality (only authorized people and systems can see your information), integrity (your information and our records can’t be silently altered), and availability (the site is there when you need it).

To support those principles we maintain β€” at minimum:

  • Encryption of data in transit between your device and our site.
  • Layered network, application, and server-level protection against malicious traffic, abuse, and automated attacks.
  • Continuous monitoring for unusual activity, with alerts reviewed by CPA staff.
  • Timely application of security updates across all components of the site.
  • Regular, retained backups with a tested restore procedure.
  • Defense-in-depth: no single control is relied upon on its own.

We don’t describe these controls in more detail here. If you’re a member with a specific concern about how your data is handled, please contact us directly.

Payment Security

All membership dues and other payments are processed by Stripe, which holds the highest level of payment-industry security certification (PCI DSS Level 1).

  • CPA never stores, processes, or has access to your credit card number.
  • Payment information goes directly from your browser to the processor’s secure systems.
  • CPA only receives a confirmation token and basic transaction details (amount, date, last four digits of the card).

Account & Access Controls

  • Accounts are protected by strong-password requirements.
  • Members imported from the previous website set a new password on first login.
  • Administrative access is limited to a small number of named individuals under a role-based model. There are no shared accounts.
  • Back-end administration tools are not exposed to regular members and sit behind additional access restrictions.
  • Sensitive administrative actions are logged so we can review what happened if we need to.

How We Handle Your Contact Information

  • Email addresses are never displayed publicly anywhere on the site. All contact flows route through server-side forms.
  • When members contact each other through CPA features (for example, the mentor directory), the site brokers the message so neither person sees the other’s email address until they choose to reply.
  • Forms are hardened against automated abuse using multiple layered techniques.

Third-Party Services That Receive Member Data

In the ordinary course of running the site, a small number of third-party services receive some of your information. We name them here so you know where your data may go:

  • Stripe β€” Payment processing. Receives only the payment data you enter during checkout.
  • Printful β€” Merchandise fulfillment. Receives your shipping name and address only when you place a merchandise order.
  • Google Analytics β€” Aggregated website traffic statistics. No personally identifiable information is collected.

Additional services are used for hostname resolution, content delivery, abuse mitigation, embedded public content (such as weather and airport data), and social-feed display. None of these receive personal information about CPA members.

Reporting a Security Concern

If you discover a security issue, or have a concern about how CPA handles your data, please reach out to the webmaster through our contact form.

Please don’t post details of potential vulnerabilities publicly (forums, social media, Discord, etc.) before contacting us. Giving us a reasonable window to investigate and fix the issue protects every member on the site.

We take every report seriously and will respond as quickly as we’re able.

See also: Data Protection Statement Β· Privacy Policy Β· Terms of Use