Security & privacy
Membership is sensitive data. We treat it that way.
In some countries, Masonic membership counts as sensitive personal data. Here is exactly how AshlarIQ protects it today.
Each lodge’s records are kept apart
Every record carries its lodge’s ID, and every page and action is limited to the signed-in officer’s own lodge. The one exception is visitor verification, which returns only a visitor’s name, lodge and standing.
Access follows the officer’s role
Admins, Secretaries, Treasurers and Members each see only what their role needs. Members see their own ID card and the lodge calendar, never other brethren’s records.
Strong sign-in
Passwords are at least 12 characters and stored only as scrypt hashes. Anyone can turn on two-step sign-in with an authenticator app, with backup codes and a “sign out everywhere” button, and AshlarIQ staff must use it. Sign-in attempts are rate limited, sessions expire after eight hours, and password links work once and expire.
Encrypted connections
Every connection uses HTTPS with HSTS, and a strict content security policy stops injected scripts from running. The platform is never indexed by search engines.
A complete audit trail
Sign-ins, changes to members and access, exports, invites, emailed summonses and visitor checks are all recorded, so officers can see who did what, and when.
Ritual stays off-platform
There is no ritual feature, minutes are an administrative record only, and our terms forbid uploading ritual.
Data protection
Designed with GDPR, Thailand’s PDPA and similar laws in mind.
Your lodge is the data controller. AshlarIQ processes members’ data only to run the service for your lodge.
- Visitor checks share only name, lodge and standing: never addresses, phone numbers or dues
- Higher bodies see nothing today; future Grand & Provincial views will need the lodge’s explicit grant
- The database is backed up before every release
- Outgoing officers lose elevated access at handover
- AshlarIQ staff support actions are recorded in the audit log
- Members and dues can be exported to CSV at any time
- No sale of member data, and no advertising, ever
Questions
About security and privacy
- Does AshlarIQ store ritual?
- No. Ritual stays off-platform by design. There is no ritual feature, minutes are an administrative record only, and our terms forbid uploading ritual. Masonic Education carries non-esoteric lessons only, and every lesson a lodge writes is confirmed ritual-free.
- Who can see our data?
- Only your own officers, according to their roles. Every lodge’s or body’s records are separated from every other’s, and higher bodies see data only where the lodge or body grants explicit permission. AshlarIQ staff access an account only for support, and every action is recorded in an audit log.
- How does visitor verification protect privacy?
- When a visiting brother is scanned in, the host learns only his name, his home lodge or body and whether he is in good standing. His address, phone number and dues history are never shared, and each check is logged.
- Can members pay their dues online?
- Yes, with Pay in Perfect Ashlar. Members pay dues, joining fees and event bookings by card through your lodge’s own Stripe account, so the money goes straight to the lodge; or they pay by bank transfer or PromptPay and send a photo of the slip, which the Treasurer checks and approves. Either way the payment lands in the Treasurer’s records and the member gets a PDF receipt by email. Cash payments recorded by the Treasurer get the same receipt.
- Can we check guests in at the door of a dinner or ladies’ night?
- Yes. Every booking comes with a QR pass on the member’s phone that covers their guests. At the door, an officer scans it with their own phone’s camera (no app or special scanner), sees who has paid, and anyone who forgot their pass is ticked off a list. When an event is full, members join a waiting list and are booked automatically, in turn, when seats come free.
- Can we get our records out for the committee or the auditors?
- Yes. Reports turns the member register, attendance, the year’s dues, arrears, payments received and events into an Excel file (with the numbers kept as numbers), a print-ready PDF with your lodge’s name and logo, or CSV. Every download is recorded in the audit log.
- How is the platform secured?
- All traffic is encrypted (HTTPS with HSTS), passwords are hashed with scrypt, sign-in attempts are rate limited, anyone can turn on two-step sign-in with an authenticator app (with backup codes and “sign out everywhere”), sessions expire after eight hours, and a strict content security policy blocks injected scripts. The database is backed up before every release.
Reporting a vulnerability
If you believe you have found a security issue, please email hello@ashlariq.com with the subject “Security report”. We acknowledge reports promptly and keep you informed while we investigate. Please don’t access other people’s data or disrupt the service. Our contact details are also published in security.txt.
Run your lodge, chapter or order on AshlarIQ.
Rough Ashlar is free for good, and every new lodge gets Perfect Ashlar free for 7 days. No card needed, and your register can be imported in minutes.