Legal
Trust Center
Last updated September 28, 2026
Your donors trust you with their generosity. You're trusting us with their information. We take that seriously.
We'd rather be clear than impressive, so this page shows exactly what's in place today and what's on the way, with dates. It isn't a certification or audit report, and we won't pretend it is.
Security contact: security@givevery.com · Privacy contact: privacy@givevery.com
The short version
| Data residency | Primary database, authentication and file storage in Canada (AWS ca-central-1, Montréal) |
|---|---|
| Card data | Handled entirely by Stripe (PCI DSS Level 1). We never see or store card numbers. |
| Authentication | MFA required for every dashboard user |
| Tenant isolation | Postgres row-level security: every nonprofit's data is walled off |
| Encryption | TLS 1.2+ in transit; AES-256 at rest |
| Breach notification | To you within 48 hours of us becoming aware |
| Subprocessor changes | 30 days' advance notice |
| AI widget builder | Off by default. Anthropic (Claude API) receives prompts and schema metadata only when you opt in — not donor rows |
| Salesforce CRM | Off until you connect it. Donor and gift fields go to your Salesforce org only |
| SOC 2 | Type I targeted by Q3 2027. Criteria: Security, Availability, Confidentiality, Privacy, and Processing Integrity (see below) |
Where we stand on compliance
| Framework | Status | What this means |
|---|---|---|
| SOC 2 (Security, Availability, Confidentiality, Privacy, Processing Integrity) | In progress. Controls designed to the AICPA Trust Services Criteria; Type I audit targeted by Q3 2027, followed by Type II | We haven't been audited yet, and we're telling you so. The control mapping below shows how our current practices line up with the criteria. Processing Integrity covers online Stripe-backed gifts and tax-receipt issuance, not card authorization, CRA legal opinion, manual/CSV gifts, Salesforce sync, or CSV import accuracy. |
| GDPR / UK GDPR | Program in place | We act as processor for donor data under our DPA, which includes the EU Standard Contractual Clauses and UK Addendum. Canada has partial EU adequacy status. |
| Québec Law 25 | Program in place | Named person in charge of personal information; confidentiality-incident procedure and register; privacy impact assessment support for transfers outside Québec; analytics off by default; data portability. |
| PIPEDA and BC PIPA | Program in place | Privacy Officer accountable; breach assessment and notification procedures; access and correction rights. |
| PCI DSS | Card data outsourced to Stripe | Payment fields are served by Stripe, so card data never touches our servers. Our annual PCI self-assessment (SAQ A) is in progress. |
| CCPA / U.S. state laws | Service-provider terms in place | No selling or sharing of personal information. |
"Program in place" means we've implemented the policies and controls these laws require. None of these laws comes with a formal certificate, so be wary of anyone who claims one.
Your data, protected
- Proudly Canadian hosting. Your data is stored in Canada. Some processing, such as application hosting, email delivery and error monitoring, happens in the United States. See the full subprocessor list.
- Only what's needed. We collect what it takes to process gifts, issue receipts and power your insights. Nothing more.
- Tenant isolation. Every table holding customer data is protected by row-level security policies, so no nonprofit can ever see another's data.
- Yours to take with you. Export your data at any time. If you leave, you have 60 days to export, then we delete it within 30.
- No selling. No ads. No AI training. Not on your data, not on your donors'.
Inside the product
- MFA enforced for all dashboard users; minimum 12-character passwords.
- Rate limiting on APIs and donation endpoints, plus Stripe fraud screening, to stop card-testing and abuse.
- Every production change goes through a pull request with required CI checks.
- Secrets stored in managed environment variables, never in source code.
- Automated dependency vulnerability scanning.
- Error monitoring with personal-information scrubbing.
Under the hood
- Built on managed providers with independent SOC 2 Type II and/or ISO 27001 attestations (Supabase, Vercel, Stripe, AWS).
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Managed, automated database backups (point-in-time recovery is not enabled on the current plan).
- Production access limited to authorized engineers, using MFA.
If something goes wrong
- Security-relevant events recorded in audit logs, kept for 1 year.
- Documented incident response procedure covering triage, containment, investigation, notification and post-incident review.
- We tell you within 48 hours of becoming aware of an incident affecting your data. We'll help with your own notifications to the CAI (Québec), the OPC (Canada) and EU/UK regulators.
- A register of confidentiality incidents, kept as required by Québec Law 25 and PIPEDA.
Our people and partners
- All personnel are bound by confidentiality obligations; access is removed promptly when someone leaves.
- Subprocessors are reviewed for security before we engage them and are bound by data-protection agreements.
Responsible use of AI
The overview AI widget builder uses Anthropic's Claude API server-side. It is disabled until you turn it on in Settings → Privacy. We send only your prompt and schema metadata needed to suggest a widget; widgets load donation metrics from Givevery after they are created. We do not send donor rows to Anthropic, and we do not use Customer Data to train models. See our Subprocessors page.
Optional Salesforce CRM
When you connect Salesforce from Integrations, Givevery sends donor and gift records one-way into your org (Nonprofit Cloud, NPSP, or standard objects) as you configure. OAuth tokens are encrypted at rest. Disconnecting revokes tokens and stops new syncs; it does not delete records already written in Salesforce. Salesforce is listed on our Subprocessors page.
What's on the way
| Item | Status | Target |
|---|---|---|
| Written information security policy set | In place | Acknowledgements recorded on joining and annually |
| Security awareness training (read policies + acknowledgement) | In progress | Q4 2026 |
| Quarterly access reviews | In progress | Q4 2026 |
| PCI DSS SAQ A self-assessment | In progress | Q4 2026 |
| Public status page (Better Stack) | In progress | This week |
| WCAG 2.2 AA accessibility review of donation forms | Planned | Q1 2027 |
| Documented business continuity and disaster recovery plan, with restore testing | Planned | Q1 2027 |
| SOC 2 Type I report | Planned | By Q3 2027 |
| SOC 2 Type II report | Planned | 6–12 months after Type I |
SOC 2 control mapping
How our controls map to the AICPA 2017 Trust Services Criteria (revised 2022).
| Criteria | Area | givevery controls | Status |
|---|---|---|---|
| CC1 | Control environment | Mo Tabesh (CEO) is Privacy Officer; Yuriy Rashnikov is engineering and security owner; personnel confidentiality obligations; code of conduct | In place / acknowledgements in progress |
| CC2 | Communication and information | Public Trust Center, Privacy Policy, DPA and subprocessor list; security@ and privacy@ contacts; customer notification commitments | In place |
| CC3 | Risk assessment | Annual risk assessment, and privacy impact assessments for new processing and transfers outside Québec | In progress |
| CC4 | Monitoring activities | Audit logs; error monitoring; periodic control self-review ahead of SOC 2 audit | In place / formal review in progress |
| CC5 | Control activities | Written security policies mapped to these controls | In place |
| CC6 | Logical and physical access | MFA; row-level security; least privilege; prompt offboarding; physical security inherited from AWS, Supabase and Vercel | In place / quarterly reviews in progress |
| CC7 | System operations | Error and performance monitoring; rate limiting; incident response procedure; confidentiality-incident register | In place |
| CC8 | Change management | Code review before production deployment; version control; automated dependency scanning | In place |
| CC9 | Risk mitigation and vendors | Vendor security review; data-protection agreements with all subprocessors; 30-day change notice | In place |
| A1 | Availability | Managed infrastructure with redundancy; automated backups; 99.5% availability target | In place / DR testing planned |
| C1 | Confidentiality | Encryption; tenant isolation; deletion on termination; NDAs | In place |
| P1–P8 | Privacy | Public privacy policy, DPA, subprocessors, DSAR export/deletion, named Privacy Officer | In place / counsel review outstanding |
| PI1 | Processing Integrity | Stripe is source of truth for online gifts; idempotent donation rows; queued/retried tax receipts; post-donation data bound to a succeeded payment | In place |
Doing your due diligence? We'll help.
Email security@givevery.com for:
- our completed security questionnaire (we're happy to complete yours);
- the Data Processing Addendum, countersigned;
- a Québec Law 25 transfer information package, to support your privacy impact assessment;
- policy summaries, and, once available, the SOC 2 report and PCI SAQ A (under NDA).
Found a vulnerability? Tell us.
If you believe you've found a security vulnerability, please email security@givevery.com with details and steps to reproduce. Please give us reasonable time to fix it before disclosing it publicly, and don't access or modify other users' data. We won't take legal action against good-faith research that follows these guidelines.
Related: Privacy Policy · Terms of Service · Subprocessors · Data Processing Addendum · Cookie Policy · Acceptable Use Policy