How i4a protects your association's data.
Last updated Aug 27, 2026
i4a is hosted on servers located in the United States. All traffic between your members, your staff and our servers is encrypted in transit using TLS (256-bit SSL). Each client's data is kept in its own separate database; no client shares a database with another. Database servers have no public IP addresses and are reachable only from i4a's own web servers. Traffic from high-risk countries is blocked at the network edge, so a stolen password cannot be used from a blocked location.
Data is backed up every four hours. We maintain a 99.9% uptime commitment. Backups are kept on separate storage from the production servers and are used to restore service in the event of a hardware failure. Membership, registration, financial and page content data are backed up every four hours; uploaded files such as PDFs are backed up daily. Servers run on solid-state storage behind redundant firewalls, with dual internet connections, battery backup and generator power, and remote monitoring of critical systems. Because every server is virtualised, a lost physical machine can be restored to new hardware within hours.
Your staff sign in with individual accounts. Administrators can set each staff user to full access or restricted access, and restricted users see only the screens they have been granted. Every staff login is recorded, and a login history for your account is available from i4a on request. Member passwords are stored using bcrypt hashing and are never stored or transmitted in plain text.
i4a supports single sign-on with OAuth 2.0 and OpenID Connect, so your members can sign in once and move between your website, learning management system, community platform and other connected services. Our REST API uses per-session authentication keys that expire after four hours, and API access can be enabled only by an i4a administrator.
i4a servers are housed in a Tier III colocation facility in the United States with 24/7 guarded access, badge and biometric entry, mantrap entry controls and locked server racks. Rack access is limited to approved personnel.
i4a does not store credit card numbers. Card data is handled by our PCI DSS Level 1 certified payment processor, 8am AffiniPay (formerly AffiniPay), and never touches i4a servers.
i4a applies security patches to its application platform and servers on a regular schedule. Our development team reviews and tests every change before it is released to client sites.
You can export your association's data at any time from the administrative area. If you leave i4a, we will provide a complete export of your data and delete it from our systems on request.
i4a does not currently hold a SOC 2 report. We are glad to complete your organization's security questionnaire and to discuss our practices with your IT or compliance staff. Contact us at support@i4a.com.
Yes, in transit using TLS. Ask us about encryption at rest for your specific hosting configuration.
On servers in the United States.
Yes, OAuth 2.0 and OpenID Connect.
Only with the service providers needed to run the platform, such as our payment processor, and only for that purpose.
Yes, at any time.