Security at Jigsaw

Security at Jigsaw

Organizations trust us with sensitive sexual abuse safety data. We take that responsibility seriously — with encryption, access controls, audit trails, and infrastructure designed to keep your information protected at every layer.

Our commitment

Jigsaw exists to help organizations prove their sexual abuse safety governance is working. The data behind that proof — review dates, meeting records, incident responses, personnel details — demands the same rigor we expect from our clients.

Security isn’t a feature we bolted on. It’s built into every layer: how data is stored, who can access it, how it moves between systems, and how we monitor what happens to it.

We also believe the data organizations entrust to us can — when properly anonymized — help the entire field get better at managing sexual abuse risk. We’re building towards cross-organization analytics that identify what works and what doesn’t, so that every organization on the platform benefits from the collective experience of all of them. We do this transparently, with rigorous anonymization, and we explain exactly how below.

Pillar 1: Encryption - Your data is protected in transit and at rest.

In transit

All connections to Jigsaw are encrypted with TLS 1.2 or higher. We enforce HTTPS across the entire platform via HSTS (HTTP Strict Transport Security), which means browsers are instructed to never connect over an unencrypted channel — even if someone types a plain HTTP address.

At rest

Your data is stored on encrypted disk volumes provided by our hosting infrastructure. Database backups are encrypted and stored in geographically separated data centers.

Payment data

Jigsaw never stores credit card numbers. All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. Card details are entered directly into Stripe’s secure elements and never touch our servers.

Pillar 2: Access Control - People only see what they're supposed to see.

Group-scoped data isolation

Every organization on Jigsaw operates within its own isolated group. Form submissions, reviews, meeting records, and incident data are scoped to the group that created them. Users in Organization A cannot see data belonging to Organization B — there is no shared data space.

Role-based permissions

Access within each organization follows defined roles. Group administrators manage their team, while standard members interact with forms and dashboards relevant to their responsibilities. Administrative functions are restricted to authorized users.

Umbrella oversight with consent

When a parent body (such as an NGB, diocese, or franchisor) needs visibility into affiliate organizations’ governance, this is governed by an explicit consent mechanism. Affiliates must actively grant access, and the scope of shared data is clearly defined. Consent can be reviewed and revoked at any time.

Pillar 3: Authentication - Verifying identity before granting access.

Secure session management

User sessions are managed through secure, httpOnly cookies with strict same-site policies. Sessions expire after periods of inactivity, and authentication tokens are time-limited and single-use to prevent replay attacks.

CSRF protection

All state-changing operations are protected by cryptographic nonce tokens, preventing cross-site request forgery attacks. Every form submission and administrative action is verified against a unique, time-limited token tied to the user’s session.

Webhook authentication

Inbound webhooks from third-party systems are authenticated using HMAC signature verification. Payloads are validated against a shared secret using constant-time comparison to prevent timing attacks. Requests that fail verification are rejected and logged.

Pillar 4: Data Handling - Careful stewardship from collection to storage.

Input validation & sanitization

All user-submitted data is validated, sanitized, and escaped before being stored or displayed. Database queries use parameterized statements to prevent SQL injection. Output is escaped at the point of rendering to prevent cross-site scripting.

Audit trails

Governance data — review completions, meeting attendance, policy updates, incident responses — is timestamped and attributed. The GMR itself is a continuous audit trail: every data point behind a Grade, Coverage, Rhythm, or Vigilance badge is traceable to a specific form submission by a specific user at a specific time.

Data minimization

We collect only the information necessary to operate the platform and calculate governance ratings. Diagnostic logs are stripped of personally identifiable information. Error reporting uses anonymized identifiers rather than email addresses or names.

Consent management

Data sharing between organizations operates on an explicit consent model. Consent records are stored with full audit history, including who granted consent, when, and the scope of data shared. Consent can be modified or withdrawn at any time, with changes taking immediate effect.

Pillar 5: Infrastructure - Reliable, monitored, and regularly backed up.

Hosting

Jigsaw is hosted on SiteGround’s managed platform, which provides server-level firewalls, automated security patches, intrusion detection, and 24/7 infrastructure monitoring. Servers are located in secure data centers with physical access controls.

Backups

Automated daily backups are maintained with a 30-day retention window. Backups are stored separately from the production environment, enabling recovery in the event of data loss, corruption, or a security incident.

Security headers

The platform enforces a comprehensive set of HTTP security headers including strict transport security, frame protection, referrer policies, and permission restrictions. These headers instruct browsers to apply additional protections that defend against common web attacks.

Rate limiting

API endpoints and webhook receivers are protected by rate limiting to defend against abuse and denial-of-service attempts. Requests that exceed defined thresholds are rejected with appropriate status codes and logged for review.

Pillar 6: Research & Anonymized Analytics - Turning collective experience into better sexual abuse safety for everyone.

Why we do this

Jigsaw collects detailed information about how organizations understand their risks, how they manage those risks, and how well their risk management is performing. Across enough organizations, this data can reveal which governance practices actually work — and which don’t. We believe this knowledge should exist, and that the organizations contributing to it should be the first to benefit from it.

What we analyze

We analyze three categories of anonymized data: organizational context (the nature of the organization and its risk landscape), governance configuration (what controls and practices are in place), and governance performance (how consistently those practices are followed and how effectively issues are resolved). We never analyze data that could identify a specific organization, individual, or incident.

How anonymization works

Before any data leaves the Jigsaw platform for analysis, it passes through an anonymization layer that irreversibly removes identifying information. Organization names, personnel names, email addresses, and location details are stripped entirely. Organization size is reported as a range rather than an exact figure. Each organization is represented by a random identifier that cannot be traced back without access to the production database, which the analytics environment never has.

Separation of environments

Anonymized analytics data is stored in a separate, dedicated environment with its own access controls. The analytics environment cannot query the production database. Data flows in one direction only — from the platform to the analytics environment — after anonymization. There is no path for analytics data to flow back to the platform in a way that could re-identify an organization.

What we publish

Insights derived from cross-organization analytics are shared as aggregated findings — patterns, benchmarks, and evidence-based guidance that inform the SAM Risk Body of Knowledge and help all organizations on the platform improve their sexual abuse safety governance. We never publish data at a level of detail that could identify any individual organization.

Where we are today

We are building this capability in stages. Our current focus is on establishing the anonymization and data capture infrastructure so that no early data is lost. Cross-organization analysis will begin when sufficient data has been collected to produce meaningful, statistically sound insights. We will update this page as each stage is completed.

Vendor Security

We choose technology partners who meet recognized security standards. Every third-party service that handles your data maintains independent security certifications.

Stripe

Payment processing

PCI DSS Level 1 • SOC 2

SiteGround

Hosting infrastructure

ISO 27001

Airtable

Registration pipeline

SOC 2 Type II

Google Cloud

Anonymized analytics

ISO 27001 • SOC 2

Questions about Security?

If you have questions about how we protect your data, or if you need to report a security concern, we’re here to help.