How the platform is protected
- All traffic is TLS; data is encrypted at rest by our infrastructure vendors.
- Sign-in runs on Supabase Auth: passkey-grade OAuth (Google, Microsoft, Apple), one-time email and SMS codes, and per-organization SAML single sign-on for enterprises.
- Organization roles gate every admin surface; staff (HQ) access is separately gated and audited.
- Partner API keys are stored as SHA-256 hashes and shown once at creation; webhooks are HMAC-SHA256 signed with per-organization secrets and timestamped against replay.
- Admin actions land in an audit log the organization can review.
Report a vulnerability
If you believe you’ve found a security issue, email security@corporategivinghub.com with steps to reproduce. Please don’t access data that isn’t yours, and give us a reasonable window to fix before public disclosure. We reply within 3 business days, and we credit researchers who help us (with permission).
In scope
corporategivinghub.com, api.corporategivinghub.com, auth.corporategivinghub.com, and the partner API surface. Out of scope: volumetric denial of service, social engineering of our users, and third-party services we integrate with (report those to the vendor).
Corporate Giving Hub · every hour of good, counted