Corporate Giving HubEnterprise specification

The complete corporate giving platform

One hub for your entire giving footprint. Employees log volunteer hours in seconds, administrators approve with full context, and your impact becomes numbers, maps, certificates, and reports that stand up in a boardroom. Free for individuals. Built to run programs of any size.

Issued for
Corporations, foundations, and churches

Enterprise specificationCapability

Run the program

Every hour, reviewed and trusted

  • A guided log flow employees finish in under a minute: who served, where, when, what, how long, photos
  • Approval queues with drill in review, reviewer notes, and embedded admin to volunteer chat
  • Bulk team event logging, custom roles, org rules and reminders, and announcement broadcasts
  • People management with lifecycle states, CSV roster import, and engagement insights
Plate 1The log-hours form, past the rules gate
Plate 2A submission mid-decision

Recognize people

Recognition that feels earned

  • Award tiers you define, aligned to the President’s Volunteer Service Award model
  • A certificate studio with premium guilloche seals, typography, borders, and signature upload
  • Automatic certificate email the moment a volunteer crosses a tier
  • Service awards, celebration moments, and a social activity hub for sharing the work
Plate 3The certificate, with its seals and signatories
Plate 4A volunteer’s own dashboard and award ladder

Prove the impact

Numbers a board believes

  • Live dashboards with clickable drill downs from any tile to the underlying records
  • Breakdowns by department, business region, cost center, title, country, and category
  • People served totals, dollar value of service, exportable reports, and a shareable impact page
  • An organization directory of every place served: verified 501(c)(3) status, hours, top volunteers
Plate 5The console home: the year, its goal and its pace
Plate 6Hours and volunteers by month, with year-on-year deltas

Enterprise specificationInterfaces

Plays beautifully with the systems you already run

A live enterprise deployment already runs this way: employees log hours inside their company’s own app, submissions land in the Hub’s approval queue, decisions and messages flow back instantly over signed webhooks, and the form itself is shaped by what administrators configure here.

  • SAML single sign on

    Connect Microsoft Entra, Okta, Google Workspace, or any SAML identity provider per organization. Employees on your email domain are routed straight to your own login. Setup takes minutes from the admin console.

  • Partner REST API

    Submit volunteer hours from your own employee app, sync opportunity signups, relay two way messages between admins and employees, and pull the shared gallery. API keys are minted in the console and stored only as hashes.

  • Signed webhooks

    Approvals, rejections, admin messages, announcements, account provisioning, and form schema changes are pushed to your systems as HMAC SHA256 signed events with automatic retries. Your app always reflects the truth.

  • HRIS provisioning

    Create employee accounts from your HR system with department, job title, business region, cost center, city, and country. Every attribute lights up a reporting dimension. Provisioning is idempotent and safe to re run.

  • Web push and email

    Decisions, messages, and announcements reach employees on the notification tray of every enrolled device, plus branded transactional email from your program.

  • Google Maps

    Locations resolve to coordinates on our servers, through Google Maps Platform when a server key is configured and OpenStreetMap when it is not, so multinational teams see their footprint on a world map by country and city. Pins for organizations in your directory come from Google Places and need that key.

Enterprise specificationSafeguards

Security your IT team will sign off on

Encryption in transit and at rest. Role gated admin surfaces with an audit log of every administrative action. API keys stored only as SHA256 hashes and shown once. Webhooks HMAC SHA256 signed with per organization secrets, carrying a timestamp inside the signature so the receiving system can reject a stale or replayed delivery. A published responsible disclosure policy. Data practices written in plain language, including exactly what your employer can and cannot see.

The detail is in the security notice and the privacy notice.

  • Google, Microsoft, and Apple sign in on Supabase Auth
  • Per organization SAML SSO with domain routing
  • Organization roles plus custom role labels for your program
  • Self pruning push subscriptions and revocable API keys
  • Plain language privacy, terms, and security pages

Enterprise specificationQuestions

Questions

  1. Question 1

    What is Corporate Giving Hub?

    Corporate Giving Hub is a complete corporate giving platform. Employees log volunteer hours in a guided flow, administrators review and approve them, and the organization gets live analytics, recognition tools, printable award certificates, and exportable impact reports. Individuals and families can use it free, and organizations of any size can run their whole program on it.

  2. Question 2

    How do employees sign in?

    Every mainstream option is supported: Google, Microsoft, and Apple sign in, one time email codes, SMS codes, and per organization SAML single sign on with providers like Microsoft Entra, Okta, and Google Workspace. Enterprises can route employees by work email domain straight to their own identity provider.

  3. Question 3

    Can it connect to our existing employee app or HR system?

    Yes. A REST partner API lets your internal apps submit volunteer hours, provision employee accounts with HR attributes such as department, region, and cost center, and receive HMAC signed webhooks for approvals, rejections, messages, announcements, and schema changes. Form questions configured by your administrators flow to partner apps automatically.

  4. Question 4

    Does it support multiple languages?

    The platform ships in 12 languages: English, Spanish, French, German, Portuguese, Italian, Chinese, Japanese, Korean, Arabic, Hindi, and Russian, with full right to left support for Arabic.

  5. Question 5

    Can we brand it as our own?

    Yes. Each organization gets a white label portal on its own subdomain with its logo, brand colors, custom award tiers, and custom log questions. Your employees see your program, not ours.

  6. Question 6

    Where is our data stored?

    All application data lives in the United States, in the US East region (Northern Virginia). The database is Neon Postgres on AWS us-east-1 with point in time recovery, the API runs on Fly.io in Ashburn, photos and media live in Cloudflare R2 in Eastern North America, and the web tier is served by Vercel with a global edge. Traffic is encrypted with TLS and data is encrypted at rest by every storage vendor.

  7. Question 7

    Can we feed the data into our own data warehouse?

    Yes, three ways. CSV exports on demand from the reporting screens, the REST partner API for pulling records programmatically, and HMAC signed webhooks that stream every approval, rejection, message, and account event to your systems in real time. Together they keep a warehouse current without direct database access, which stays closed as a security boundary.

  8. Question 8

    What is the technology stack and how is security handled?

    TypeScript end to end: Next.js on the web, a Hono and tRPC API, and Postgres through the Drizzle ORM. Identity runs on dedicated auth infrastructure with Google, Microsoft, and Apple sign in, one time codes, and per organization SAML. API keys are stored only as SHA256 hashes, webhooks are HMAC SHA256 signed with per organization secrets and every delivery carries a timestamp inside the signature so the receiving system can reject a stale or replayed one, admin actions land in an audit log, and a responsible disclosure policy is published at corporategivinghub.com/security.

  9. Question 9

    How is the platform maintained?

    The codebase is version controlled and a release is cut by hand. There is no CI pipeline, so the full type check, test suite and production build is run before a release goes out rather than on every push. Database migrations run as a release step before the new machines take traffic, and a failed migration aborts the deploy so the version already running keeps serving. Health checks poll the API every fifteen seconds and pull any machine that cannot reach the database out of rotation, and our infrastructure providers apply security patches at the platform layer. Updates reach you without any action on your side.

  10. Question 10

    How are nonprofit organizations verified?

    When a place is registered as a 501(c)(3), its EIN is checked against IRS records. Every place a team serves builds a profile with address, category, hours served, and top volunteers.

Your people already do good. Start counting it.

Set up an organization in minutes. Invite by SSO, email domain, or code. Free for individuals and families, powerful for the whole enterprise.