Security

How we protect your data and ensure secure donation processing.

Last Updated: February 2, 2026

Our Security Commitment

Secure by Design

At DonateZap, security is built into everything we do. We implement industry-leading security measures to protect your organization's and donors' sensitive information.

Payment Security

PCI DSS Compliance

DonateZap partners with Stripe, a PCI Service Provider Level 1 certified payment processor — the highest level of certification in the payments industry.

  • Sensitive payment data never touches our servers
  • All payment information is encrypted using industry-standard TLS
  • Tokenization of payment methods for secure recurring donations
  • Fraud detection and prevention systems
  • Real-time transaction monitoring

Data Protection

How We Safeguard Your Data

  • Encryption: All sensitive data is encrypted both in transit and at rest
  • Secure Infrastructure: Our platform is hosted with multiple security layers
  • Access Controls: Strict role-based access controls
  • Regular Backups: Automated, encrypted backups
  • Monitoring: 24/7 security monitoring

Account Security

We provide multiple features to help you secure your DonateZap account:

  • Two-Factor Authentication (2FA): Add an extra layer of security
  • Strong Password Requirements: Enforcing complex passwords
  • Session Management: Automatic session timeouts
  • Account Activity Logs: Track login attempts and account changes
  • IP Restrictions: Optional feature to limit login access

Security Certifications

Industry Standards

  • SOC 2 Type II compliance (via our infrastructure providers)
  • GDPR compliance for European data subjects
  • CCPA compliance for California residents
  • Regular penetration testing
  • Vulnerability scanning and remediation

Security Testing

We continuously test and improve our security measures through:

  • Regular penetration testing by independent security experts
  • Automated vulnerability scanning
  • Code security reviews
  • Security incident response drills

Reporting Security Concerns

Responsible Disclosure

If you believe you've discovered a security vulnerability in our platform, please report it to us immediately at security@thedonation.io.

  • Provide enough information to reproduce the issue
  • Allow us reasonable time to address the vulnerability before public disclosure
  • Avoid privacy violations, destruction of data, or interruption of services

Contact Our Security Team

For security-related questions or concerns, please contact: