Security

Guarded, quietly.

Last updated 2026-07-26

How the platform is protected

  • All traffic is TLS; data is encrypted at rest by our infrastructure vendors.
  • Sign-in runs on Supabase Auth: passkey-grade OAuth (Google, Microsoft, Apple), one-time email and SMS codes, and per-organization SAML single sign-on for enterprises.
  • Organization roles gate every admin surface; staff (HQ) access is separately gated and audited.
  • Partner API keys are stored as SHA-256 hashes and shown once at creation; webhooks are HMAC-SHA256 signed with per-organization secrets and timestamped against replay.
  • Admin actions land in an audit log the organization can review.

Report a vulnerability

If you believe you’ve found a security issue, email security@corporategivinghub.com with steps to reproduce. Please don’t access data that isn’t yours, and give us a reasonable window to fix before public disclosure. We reply within 3 business days, and we credit researchers who help us (with permission).

In scope

corporategivinghub.com, api.corporategivinghub.com, auth.corporategivinghub.com, and the partner API surface. Out of scope: volumetric denial of service, social engineering of our users, and third-party services we integrate with (report those to the vendor).

Corporate Giving Hub · every hour of good, counted