The Jogajog blog

Every feature, explained properly — how it works, why it's built that way, and how organizations across Bangladesh put it to work.

Security

Security questions to ask ANY member-app vendor (including us)

Ask: where's the tenant isolation enforced? Is there a password database? Can I export everything today? Is there a public status page? When was…

Security

Your data rights: export, retention and deletion in writing

Organizations can export everything at any time; on closure, data stays exportable for a 90-day retention window and is then deleted; wallet refunds follow…

Security

Sessions, refresh and the 15-minute token: security you never see

Access tokens live fifteen minutes; sessions renew silently through rotating refresh tokens for up to thirty days of use. Stolen tokens age out fast,…

Security

No-enumeration design: why the app won’t say “number not found”

Ask for a code with any number or email and the screen responds identically whether it exists or not. Attackers can't harvest your member…

Security

Fair-use quotas as a security control

Per-organization caps — broadcasts per day, rows per import — turn a compromised account or runaway script from a platform incident into a contained…

Security

Kill switches: how a platform stays calm during incidents

Staff can pause specific capabilities — payments, broadcasts, signups — in seconds, globally or for one organization, without redeploying anything. Members see

Security

status.jogajog.app: why we show you our uptime

The public status page checks the live platform from your own browser — no marketing-department weather report. When something's wrong, you see it there…

Security

Backups you can trust: nightly, verified, restore-drilled

The platform backs up nightly, verifies archive integrity, retains a rolling window with off-site copies, and — the part most vendors skip — actually…

Security

The append-only audit log as a security instrument

Security isn't only prevention — it's attribution. Every administrative action is recorded append-only with actor and timestamp, so incidents reconstruct in min

Security

Database-level isolation: what multi-tenant safety really means

Every organization's rows are walled off by row-level security enforced in the database engine itself — not by application code promising to behave. A…

Reading is good. A live demo is better.

Send your member spreadsheet — see your own branded app this week.

Get your free demo