Free Grant Finder, forever — no card, no catch. Premium plans now in early access.

Legal & Trust

Security

Last updated: July 22, 2026

Last updated: July 21, 2026

Nonprofits trust CharityIQ with sensitive information — program data, beneficiary details, financials, and draft applications. Protecting that information is central to how we build. This page explains the safeguards we have in place. It is written in plain language; if you need a security questionnaire completed or want our current sub-processor list, email hello@charityiq.us.

Hosting and infrastructure

CharityIQ runs on enterprise-grade cloud infrastructure hosted in the United States, with processing in the European Union where applicable. Our providers maintain independently audited physical and network security (including certifications such as SOC 2 and ISO 27001 at the infrastructure level). Production systems are logically isolated, and customer data is segregated by organization.

Encryption

Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 or equivalent. Secrets and credentials are stored in dedicated secret-management systems, never in application code.

Access control

We apply least-privilege access: team members can access production data only when needed to operate or support the service, and such access is logged. Administrative access requires multi-factor authentication. Internally, access follows role-based controls and is reviewed periodically.

How your data is used with AI

CharityIQ’s AI is grounded: it draws on verified sources and cites them, and a human reviews output before it is used. We do not use your organization’s private data to train public AI models, and our AI model providers are contractually bound not to train their public models on data we send through them. See Data sources for what we ground answers in.

Backups and resilience

We maintain regular, encrypted backups to support recovery, and we design for redundancy across availability zones. We test our ability to restore service and data.

Monitoring and vulnerability management

We monitor our systems for anomalous activity, apply security patches promptly, and use automated dependency and vulnerability scanning as part of our development process. Changes to production follow code review and testing.

Compliance roadmap

CharityIQ is built to SOC 2 principles and is preparing for formal SOC 2 examination. We handle personal data in line with applicable US state privacy laws and, where relevant, the EU/UK GDPR. See our Privacy Policy and Data Processing Agreement.

Sub-processors

We use a small set of vetted vendors to operate the service — covering cloud hosting, AI model processing, payment processing, email delivery, and product analytics. Each is bound by contractual data-protection terms. A current list of named sub-processors is available on request from privacy@charityiq.us.

Incident response

We maintain an incident-response process. In the event of a personal-data breach affecting your organization, we will notify you without undue delay and provide the information you need to meet your own obligations, consistent with our Data Processing Agreement and applicable law.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to hello@charityiq.us with enough detail to reproduce it. Please give us a reasonable opportunity to remediate before any public disclosure. We are grateful to researchers who help us keep nonprofits safe.

Your part

Security is shared. Use a strong, unique password, keep your credentials confidential, enable available account protections, and remove access for people who leave your organization. Tell us immediately at hello@charityiq.us if you suspect unauthorized access.


CharityIQ is a product of CIQ Technologies Ltd, a company registered in England and Wales (company no. 17338776). Security questions? Email hello@charityiq.us.