Trust & Security
Security and trust, built in.
Donors trust you with their generosity, and you trust us with their data. Here is how we protect it.
Compliance
SOC 2
Built to the SOC 2 Trust Services Criteria. Our SOC 2 audit is in progress.
PCI-compliant payments
Card data is handled by Stripe, a PCI-DSS Level 1 provider. Givable never stores full card numbers.
GDPR & PIPEDA aligned
We support data-subject rights and use standard contractual clauses for transfers where required.
Pursuing ISO 27001
We are working toward ISO 27001 as our security program matures.
How we protect your data
Security in the details.
Encrypted in transit
TLS on every connection between you, your donors, and Givable.
Encrypted at rest
Data at rest is encrypted with AES-256.
Secure authentication
Passwords are hashed with modern algorithms. SSO is available on Enterprise.
Least-privilege access
Granular roles and permissions control who can see and do what.
Continuous monitoring
We monitor our systems for availability and unusual activity.
In-region data residency
A dedicated database in your region is available on Enterprise.
Payments handled by Stripe.
Donations are processed by Stripe, a PCI-DSS Level 1 certified provider. Card details go straight to Stripe and are never stored on Givable.
- PCI-DSS Level 1 payment processing
- Full card numbers never touch Givable
- Fraud and risk tooling built in
- Donors can optionally cover fees
Privacy and your data
Nonprofits own their donor data. We process it on your behalf, support access, correction, and deletion requests, and share it only with the subprocessors needed to run the service.
Report a vulnerability
Found a security issue? We want to hear from you. Email our team and we will respond promptly and work with you on a fix.
Questions about security?
Talk to our team about your organization's security and compliance requirements.