Skip to main content

Security and trust

Protect the mission behind every gift.

DonorBeam keeps the payment boundary clear, scopes access to the right organization, and makes fundraising activity traceable from checkout to ledger.

Contact security
Donation and identity data passing through a protected trust boundary

Our security model

Clear boundaries are stronger boundaries.

Keep payment data at the processor

Your nonprofit connects its Stripe account. Payment details go directly to Stripe and are not stored on DonorBeam servers.

Keep organizations separated

Organization-scoped relational constraints and database row-level security are designed to isolate customer records.

Give people only the access they need

Workspace membership and role assignment control who can see and change organization data.

Built into the product

Controls that follow the work.

Security is part of identity, payments, data access, and daily operations—not a separate page your team has to remember.

Identity and sessions

Invite-based enrollment, exact redirect allowlists, secure sign-in links, optional Google sign-in, and rotating sessions.

Edge protection

HTTPS, HSTS, content security policy, frame protection, and Cloudflare edge controls.

Payment integrity

Connected-account charges, signed webhooks, idempotent lifecycle records, and itemized ledger entries.

Secrets management

Provider-managed secret stores and local Keychain references; production secrets are not committed to source.

Auditability

Durable provider identifiers, checkout lifecycle records, ledger entries, and security-relevant audit events.

Operational readiness

Backup, restore, incident ownership, reconciliation, and release checks are part of the production operating process.

Independent assurance

Straight answers for your review.

DonorBeam does not currently claim SOC 2 certification, an independent penetration test, or a completed PCI attestation. Stripe-hosted payment collection is used to minimize payment-card scope.

Have a security question?

Send your review questions or a responsible vulnerability report to our security contact. Please avoid accessing or changing data that is not yours.