SECURITY

Security

UK charities trust us with sensitive data — beneficiary records, funder relationships, financial figures. Security is part of how we built the product. This page sets out our current posture.

Last reviewed: 26 April 2026.

Where your data lives

How we protect it

Encryption

Access control

Application security

AI-specific safeguards

Backup and recovery

Incident response

If a security incident affects Customer Data, we notify affected customers without undue delay (and within 72 hours wherever feasible). See our Data Processing Agreement for full breach notification terms.

Reporting a vulnerability

If you believe you’ve found a security vulnerability, email office@charityiq.co.uk with:

We acknowledge reports within 2 working days and aim to triage and respond within 10 working days. We will not pursue legal action against good-faith security researchers who follow this responsible disclosure process.

Certifications and audits

As of April 2026, we are an early-stage company and do not yet hold formal certifications (e.g., SOC 2, ISO 27001). We use the AWS Well-Architected Framework as our internal baseline and engage independent reviewers for periodic security audits. Certification milestones are on our roadmap; we’ll publish updates here.

For procurement teams

If your charity’s procurement or audit process needs a security questionnaire response or DPIA support, email office@charityiq.co.uk. We turn around security due diligence within 5 working days for active customers.