Trust & Security

Security and trust, built in.

Donors trust you with their generosity, and you trust us with their data. Here is how we protect it.

Compliance

SOC 2

Built to the SOC 2 Trust Services Criteria. Our SOC 2 audit is in progress.

PCI-compliant payments

Card data is handled by Stripe, a PCI-DSS Level 1 provider. Givable never stores full card numbers.

GDPR & PIPEDA aligned

We support data-subject rights and use standard contractual clauses for transfers where required.

Pursuing ISO 27001

We are working toward ISO 27001 as our security program matures.

How we protect your data

Security in the details.

Encrypted in transit

TLS on every connection between you, your donors, and Givable.

Encrypted at rest

Data at rest is encrypted with AES-256.

Secure authentication

Passwords are hashed with modern algorithms. SSO is available on Enterprise.

Least-privilege access

Granular roles and permissions control who can see and do what.

Continuous monitoring

We monitor our systems for availability and unusual activity.

In-region data residency

A dedicated database in your region is available on Enterprise.

Payments handled by Stripe.

Donations are processed by Stripe, a PCI-DSS Level 1 certified provider. Card details go straight to Stripe and are never stored on Givable.

  • PCI-DSS Level 1 payment processing
  • Full card numbers never touch Givable
  • Fraud and risk tooling built in
  • Donors can optionally cover fees

Privacy and your data

Nonprofits own their donor data. We process it on your behalf, support access, correction, and deletion requests, and share it only with the subprocessors needed to run the service.

Report a vulnerability

Found a security issue? We want to hear from you. Email our team and we will respond promptly and work with you on a fix.

Questions about security?

Talk to our team about your organization's security and compliance requirements.