Security & compliance

Naz.tools handles payments, signed waivers, and information about minors. Here is what we do about that.

Payments

Waivers and PHI

Waivers and the medical information they collect are protected health information in spirit even if not always in legal definition. We treat them as such.

Minors and COPPA

Audit trail

Every booking has an append-only event log: created, paid, waiver signed, checked in, checked out, refunded, cancelled. The log cannot be edited from the admin UI. If a question ever comes up about who did what when, the log answers it.

Role-based access

Permissions are composable, not all-or-nothing. A district administrator can grant a volunteer the ability to run kiosk check-in for one camp without giving them access to financial records, member data, or anything else. Today's role set includes:

Your data is yours

ECFA-aligned audit posture

For district treasurers familiar with the Evangelical Council for Financial Accountability's Seven Standards of Responsible Stewardship, here is how the platform's controls map to the standards that matter most for the operational work it touches:

This is the language a CPA or audit committee will recognize. The platform doesn't grant ECFA membership — that's a separate organizational process — but it produces the kind of records ECFA-accredited stewardship practices require.

What we don't yet have (as of beta)

Honesty matters more than marketing here:

Request beta access   Read the FAQ