Last updated: July 21, 2026
Nonprofits trust CharityIQ with sensitive information — program data, beneficiary details, financials, and draft applications. Protecting that information is central to how we build. This page explains the safeguards we have in place. It is written in plain language; if you need a security questionnaire completed or want our current sub-processor list, email hello@charityiq.us.
Hosting and infrastructure
CharityIQ runs on enterprise-grade cloud infrastructure hosted in the United States, with processing in the European Union where applicable. Our providers maintain independently audited physical and network security (including certifications such as SOC 2 and ISO 27001 at the infrastructure level). Production systems are logically isolated, and customer data is segregated by organization.
Encryption
Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 or equivalent. Secrets and credentials are stored in dedicated secret-management systems, never in application code.
Access control
We apply least-privilege access: team members can access production data only when needed to operate or support the service, and such access is logged. Administrative access requires multi-factor authentication. Internally, access follows role-based controls and is reviewed periodically.
How your data is used with AI
CharityIQ’s AI is grounded: it draws on verified sources and cites them, and a human reviews output before it is used. We do not use your organization’s private data to train public AI models, and our AI model providers are contractually bound not to train their public models on data we send through them. See Data sources for what we ground answers in.
Backups and resilience
We maintain regular, encrypted backups to support recovery, and we design for redundancy across availability zones. We test our ability to restore service and data.
Monitoring and vulnerability management
We monitor our systems for anomalous activity, apply security patches promptly, and use automated dependency and vulnerability scanning as part of our development process. Changes to production follow code review and testing.
Compliance roadmap
CharityIQ is built to SOC 2 principles and is preparing for formal SOC 2 examination. We handle personal data in line with applicable US state privacy laws and, where relevant, the EU/UK GDPR. See our Privacy Policy and Data Processing Agreement.
Sub-processors
We use a small set of vetted vendors to operate the service — covering cloud hosting, AI model processing, payment processing, email delivery, and product analytics. Each is bound by contractual data-protection terms. A current list of named sub-processors is available on request from privacy@charityiq.us.
Incident response
We maintain an incident-response process. In the event of a personal-data breach affecting your organization, we will notify you without undue delay and provide the information you need to meet your own obligations, consistent with our Data Processing Agreement and applicable law.
Responsible disclosure
If you believe you have found a security vulnerability, please report it to hello@charityiq.us with enough detail to reproduce it. Please give us a reasonable opportunity to remediate before any public disclosure. We are grateful to researchers who help us keep nonprofits safe.
Your part
Security is shared. Use a strong, unique password, keep your credentials confidential, enable available account protections, and remove access for people who leave your organization. Tell us immediately at hello@charityiq.us if you suspect unauthorized access.
CharityIQ is a product of CIQ Technologies Ltd, a company registered in England and Wales (company no. 17338776). Security questions? Email hello@charityiq.us.