Security
UK charities trust us with sensitive data — beneficiary records, funder relationships, financial figures. Security is part of how we built the product. This page sets out our current posture.
Last reviewed: 26 April 2026.
Where your data lives
- UK servers only — AWS London region (eu-west-2)
- No transfers outside the UK or EEA for Customer Data
- Tenant isolation — your charity’s data is logically separated from every other customer
- UK-incorporated — CharityIQ Ltd is registered in England and Wales; UK GDPR governs everything we do
How we protect it
Encryption
- In transit — TLS 1.3 enforced for all customer-facing endpoints
- At rest — AES-256 for all stored data, including database, backups, and file storage
- Secrets — managed via AWS KMS; no credentials in source code or logs
Access control
- Role-based access control within the platform
- Multi-factor authentication required for all CharityIQ staff with production access
- Principle of least privilege — staff have access to only what they need
- Audit logs — all administrative actions logged and retained 12 months
Application security
- Dependency scanning — automated daily, with prompt patching
- Static analysis on every commit
- Secret scanning in source code and CI
- Web Application Firewall (Cloudflare) for DDoS and common-attack mitigation
- Rate limiting on authentication and API endpoints
AI-specific safeguards
- Customer Data is not used to train AI models — neither ours nor any third party’s
- Inference happens in UK/EU regions only for customer-facing AI features
- Outputs are grounded in your verified data — every claim cites its source
- Audit trail — every prompt, source, and human approval is logged in your account
Backup and recovery
- Encrypted daily backups of all customer data
- 30-day backup retention
- Disaster recovery tested at least annually
- Documented incident response procedures
Incident response
If a security incident affects Customer Data, we notify affected customers without undue delay (and within 72 hours wherever feasible). See our Data Processing Agreement for full breach notification terms.
Reporting a vulnerability
If you believe you’ve found a security vulnerability, email office@charityiq.co.uk with:
- A clear description of the issue
- Steps to reproduce
- Any proof-of-concept code (no destructive testing, please)
We acknowledge reports within 2 working days and aim to triage and respond within 10 working days. We will not pursue legal action against good-faith security researchers who follow this responsible disclosure process.
Certifications and audits
As of April 2026, we are an early-stage company and do not yet hold formal certifications (e.g., SOC 2, ISO 27001). We use the AWS Well-Architected Framework as our internal baseline and engage independent reviewers for periodic security audits. Certification milestones are on our roadmap; we’ll publish updates here.
For procurement teams
If your charity’s procurement or audit process needs a security questionnaire response or DPIA support, email office@charityiq.co.uk. We turn around security due diligence within 5 working days for active customers.