Security and access
Access follows the audience you choose.
AcaBoost separates each organization and makes the boundary between public content, signed-in access, private documents, and shared links explicit.
Tenant isolation
Every organization operates inside its own tenant boundary. Application authorization and database tenant filters prevent one club's administrators, contacts, content, documents, and operational records from being used as another club's data.
Public website content
Website pages reach anonymous visitors only after an administrator publishes them with public visibility. Images intentionally placed in the public media library are served as public site assets, so teams should not use that library for confidential records.
Signed-in and private content
Member pages require a signed-in tenant member. Administrative workspaces and internal document preview or download routes require authentication and the applicable role or resource permission; hiding a link is never treated as authorization.
Revocable share links
A private document can be shared through a capability link when an administrator deliberately creates one. Links can be revoked and may use expiration dates, download limits, passwords, and embed restrictions. The token is the credential, so recipients should handle it like other sensitive access links.
File safeguards
Files must pass malware scanning before they can be previewed, downloaded, or embedded. Only a narrow image-and-PDF allowlist renders inline; other file types download as attachments, and inline responses receive restrictive browser security policies.
Operational controls
Role-based administration, audit records, protected authentication, tenant-scoped provider configuration, encrypted transport, backups, monitoring, and signed provider callbacks support the service. Administrators remain responsible for least-privilege roles, removing former volunteers, choosing appropriate visibility, and revoking links that are no longer needed.
Questions or reports
Review the privacy policy for data-handling details. Report a suspected vulnerability or access issue to security@acaboost.net without including passwords, access tokens, or payment card data.