- Why it matters
- When an org puts 'Sign in with Google' or 'Login with Facebook' on its donate page, every Muslim donor who clicks it creates an authenticated linkage between their identity and a Muslim charity on the books of a company whose parent holds contracts with militaries and surveillance agencies. Google's Project Maven (Pentagon AI) and Project Nimbus ($1.2B with the Israeli government, joint with Amazon), Microsoft's $21.9B IVAS Army contract, all three major US clouds (Google, Microsoft, AWS) as announced Palantir host partners. Muslim Pro / X-Mode sold prayer-app location data to US Special Operations Command in 2020. The NYPD Demographics Unit surveilled Muslim communities for years. The risk is documented, not theoretical, so we note it and encourage a privacy-respecting alternative.
- How we detect it
- Static + JS-rendered scan of the org's /donate, /login, and homepage for the script signatures of Sign in with Google (accounts.google.com/gsi/client), Sign in with Apple (appleid.cdn-apple.com), Sign in with Microsoft (login.microsoftonline.com), Login with Facebook (connect.facebook.net), and Login with Amazon (assets.loginwithamazon.com).
- What we'd love every org to have
- We flag when donor-facing pages embed mainstream surveillance-affiliated SSO and encourage a privacy-respecting alternative, we don't require removal. Alternatives worth considering (any is a meaningful upgrade): UmmahPassport SSO (Muslim-owned, charter-locked against state funding and ad business, zero-admin-visibility architecture); or an open-source privacy-first option. ZITADEL (Swiss-hosted, GDPR-respecting), Authentik (self-hostable), Keycloak (Red Hat open source, self-hostable), or Ory (open source identity primitives). Direct email signup is also fine if you don't need federated identity.
- If this applies to you, how to surface it
- This is something we flag and encourage you to reconsider, not a required removal.
- If you'd like to move off it: pick a privacy-respecting alternative. Best for the Muslim ecosystem: UmmahPassport SSO. Self-hostable: Authentik, Keycloak, Ory. Managed privacy-first: ZITADEL (Swiss). All are OIDC-compliant, wiring one in is a single config block.
- If the buttons are there because your donate-platform vendor (Stripe Checkout, Donorbox, GiveLively) loads them by default, most can be turned off in dashboard settings.
- Sign in and submit the donate-page URL if you make a change, we'll re-index.
Ask us to re-index
Once the change is live on the org website, sign in with UmmahPassport SSO and submit the supporting link. Ihsan Standard re-runs detection and lifts the tag on the next pass, typically within 5 business days.
UmmahPassport SSO live in Phase 2. Until then, the engagement-track contact form works the same way.