Security & Trust
Last updated: Feb 2024
Security and trust are at the core of everything we do. We understand the responsibility of protecting your financial data and we take it seriously. This Security and Trust page provides an overview of the measures we take to ensure the security, privacy, and integrity of your information.
We employ industry-standard security practices and technologies to safeguard your data from unauthorized access, disclosure, or modification. Our security program is designed to meet the highest standards of transparency and accountability.
This document serves as an overview of our security posture. If you have any specific questions about our security practices, please contact us at security@nonprofitbudgetbuilder.com.
Please note that this document is for informational purposes only and does not constitute a legal agreement. For our legal terms, please refer to our Terms and Conditions.
1. Our Security Philosophy
Security is not a feature for us; it is a core principle of our product. We take the following approach to security:
- Defense in depth
- Principle of least privilege
- Continuous monitoring and testing
- Security-first mindset in engineering
2. Data Ownership
You own your data. Nonprofit Budget Builder only uses your data to provide you with the services you've requested. We do not sell your personal data to third parties.
- We do not sell your personal data.
- We do not share your data with advertisers.
- We only share data with third parties to provide services you've requested.
- You can export your data or delete your account at any time.
3. Data Access Control
We maintain strict internal controls to restrict access to user data. Access is only granted when necessary to provide support or services.
- Role-based access control
- Multi-factor authentication
- Logged and audited access
- Regular access reviews
- Access revoked immediately upon termination
4. Authentication and Account Security
- Secure password hashing
- Multi-factor authentication (MFA)
- Session timeout and management
- Rate limiting and brute force protection
- Automated alerts for suspicious login activity
5. Encryption
We use industry-standard encryption to protect your data both in transit and at rest.
6. Data in transit
All communications between your device and the platform are encrypted using Secure Sockets Layer (SSL) and Transport Layer Security (TLS).
7. Data at rest
Sensitive data is encrypted at rest using industry-standard AES-256 encryption. Encryption keys are managed using dedicated key management services.
8. Hosting Infrastructure
Our platform is hosted on Amazon Web Services (AWS), which provides a secure and resilient cloud infrastructure. We utilize several AWS security features, including:
- Virtual Private Clouds (VPC)
- Network Access Control Lists (NACL)
- Security Groups
- Web Application Firewalls (WAF)
- Intrusion Detection Systems
- DDoS protection
9. System Monitoring
We monitor our systems around the clock for performance, availability, and security.
- Real-time logging and alerting
- Security event monitoring
- Vulnerability scanning
- Performance monitoring
- Uptime monitoring
10. Data Backups
We perform regular backups of our data to ensure availability and recoverability.
- Daily backups
- Backups are encrypted and stored in multiple locations for redundancy.
- Regular testing of restore procedures.
11. Personnel Practices and Background Checks
We conduct background checks on all employees and contractors, subject to local laws and regulations.
Team members receive security training and are required to follow confidentiality agreements and internal security policies.
12. Internal Systems and Security
We maintain secure internal systems to support our operations.
- Centralized identity and access management
- Secure endpoint management
- Regular patching and updates
- Network segmentation
- Malware protection
13. Subprocessors and Service Providers
We work with third-party service providers to help us deliver our services. These partners are selected for their commitment to security and privacy.
- Financial data aggregators (e.g., Plaid, MX, Finicity)
- Cloud infrastructure providers (e.g., AWS)
- Email and communication services
- Analytics and logging tools
- Customer support tools
- Payment processors
14. Incident Response
In the event of a security incident, we have an incident response plan in place to mitigate the impact and notify affected users.
- Incident identification and categorization
- Containment and eradication
- Recovery and post-incident analysis
- Notification as required by law
15. Product Governance
We follow secure software development lifecycle (SDLC) practices.
- Code reviews for all changes
- Automated security testing in CI/CD pipeline
- Regular penetration testing by third-party security firms
- Bug bounty program
16. Shared Responsibility
Security is a shared responsibility between Nonprofit Budget Builder and our users.
- Use a strong, unique password
- Enable multi-factor authentication
- Be cautious of phishing attempts
- Keep your devices and software up to date
17. Continuous Improvement
We are committed to continuously improving our security posture and adapting to the evolving threat landscape.
18. Questions?
If you have any questions or concerns about our security practices, please contact us:
- Visit our Help Center
- Contact our support team at support@nonprofitbudgetbuilder.com
- Report a security vulnerability at security@nonprofitbudgetbuilder.com
