- Why it matters
- When an org puts 'Sign in with Google' or 'Login with Facebook' on its donate page, every Muslim donor who clicks it creates an authenticated linkage between their identity and a Muslim charity on the books of a company whose parent holds contracts with militaries and surveillance agencies — Google's Project Maven (Pentagon AI) and Project Nimbus ($1.2B with the Israeli government, joint with Amazon), Microsoft's $21.9B IVAS Army contract, all three major US clouds (Google, Microsoft, AWS) as announced Palantir host partners. Muslim Pro / X-Mode sold prayer-app location data to US Special Operations Command in 2020. The NYPD Demographics Unit surveilled Muslim communities for years. The risk is documented, not theoretical.
- How we detect it
- Static + JS-rendered scan of the org's /donate, /login, and homepage for the script signatures of Sign in with Google (accounts.google.com/gsi/client), Sign in with Apple (appleid.cdn-apple.com), Sign in with Microsoft (login.microsoftonline.com), Login with Facebook (connect.facebook.net), and Login with Amazon (assets.loginwithamazon.com).
- What we'd love every org to have
- Donor-facing pages do not embed mainstream surveillance-affiliated SSO buttons. Recommended replacements (any of these is a meaningful upgrade): UmmahPassport SSO (Muslim-owned, charter-locked against state funding and ad business, zero-admin-visibility architecture); or one of the open-source privacy-first alternatives — ZITADEL (Swiss-hosted, GDPR-respecting), Authentik (self-hostable), Keycloak (Red Hat open source, self-hostable), or Ory (open source identity primitives). Direct email signup is also fine if you don't need federated identity. See the UmmahPassport privacy-comparison page for the full research-grounded contrast.
- How to improve · concrete remediation
- Audit your donate page, login page, and any other donor-facing flow for embedded Sign in with Google/Apple/Microsoft/Facebook/Amazon buttons.
- Pick a replacement that fits your stack. Best for the Muslim ecosystem: UmmahPassport SSO (Muslim-owned, charter-locked privacy). Self-hostable alternatives: Authentik, Keycloak, Ory. Managed privacy-first: ZITADEL (Swiss). All are OIDC-compliant — wiring them in is one config block.
- If they're there because your donate platform vendor (Stripe Checkout, Donorbox, GiveLively) loads them by default, talk to the vendor about disabling those options. Most can be turned off in dashboard settings.
- For the remaining email-signup flow, point your registration backend at the UmmahPassport OIDC discovery endpoint or any of the alternatives above.
- Sign in and submit the donate-page URL — we'll re-index to confirm the surveillance-SSO is no longer detected.
Ask us to re-index
Once the change is live on the org website, sign in with UmmahPassport SSO and submit the supporting link. Ihsan Standard re-runs detection and lifts the tag on the next pass — typically within 5 business days.
UmmahPassport SSO live in Phase 2. Until then, the engagement-track contact form works the same way.