๐Ÿ”’ Security & trust

Built for charity-grade trust.

Your charity's data is sensitive. We treat it that way โ€” UK-hosted, encrypted, GDPR-compliant, audited. Below is how, in plain English.

GDPR ยท UK serversICO ZA928374SOC 2 Type II in progressCyber Essentials PlusDPA on requestAnnual pen test
๐Ÿ—„

Where your data lives

Stored on Hetzner Cloud servers in Germany (EU), with daily encrypted backups to a second EU region.

  • โœ“ UK / EU only โ€” no US data transfers
  • โœ“ Daily backups, 30-day retention
  • โœ“ Customer-isolated database schemas
๐Ÿ”’

Encryption

AES-256 at rest, TLS 1.3 in transit. Hardware-backed vaults for secrets. Argon2id password hashing.

  • โœ“ AES-256 at rest
  • โœ“ TLS 1.3 in transit
  • โœ“ Argon2id password hashing
๐Ÿ“‹

Compliance

GDPR compliant, ICO registered, Cyber Essentials Plus. SOC 2 Type II audit expected Q3 2026.

  • โœ“ GDPR compliant + ICO registered
  • โœ“ Cyber Essentials Plus
  • โœ“ Annual external penetration test
๐Ÿ›ก

Access & audit

Data actions logged for 12 months on Agency plans. Least-privilege access, MFA required for staff.

  • โœ“ Per-user audit log
  • โœ“ MFA required for staff
  • โœ“ 72-hour incident notification

Subprocessors

The vendors we trust with your data. Updated 12 May 2026.

VENDORPURPOSEREGIONDATA PROCESSED
HetznerCompute & storageGermany (EU)All charity data
PostmarkTransactional emailEUEmail addresses, alerts
AnthropicAI scoring & draftsEU API regionCharity profile (no PII)
StripePaymentsEU + USBilling only
CloudflareCDN & DDoSGlobal edgePublic marketing pages only

Trust Report

Documentation and live status available on request.

Status page

Documentation and live status available on request.

Vulnerability disclosure

Documentation and live status available on request.

Request DPA or security pack โ†’