nonprofit budget builder™

Security & Trust

Last updated: Feb 2024

Security and trust are at the core of everything we do. We understand the responsibility of protecting your financial data and we take it seriously. This Security and Trust page provides an overview of the measures we take to ensure the security, privacy, and integrity of your information.

We employ industry-standard security practices and technologies to safeguard your data from unauthorized access, disclosure, or modification. Our security program is designed to meet the highest standards of transparency and accountability.

This document serves as an overview of our security posture. If you have any specific questions about our security practices, please contact us at security@nonprofitbudgetbuilder.com.

Please note that this document is for informational purposes only and does not constitute a legal agreement. For our legal terms, please refer to our Terms and Conditions.

1. Our Security Philosophy

Security is not a feature for us; it is a core principle of our product. We take the following approach to security:

  • Defense in depth
  • Principle of least privilege
  • Continuous monitoring and testing
  • Security-first mindset in engineering

2. Data Ownership

You own your data. Nonprofit Budget Builder only uses your data to provide you with the services you've requested. We do not sell your personal data to third parties.

  • We do not sell your personal data.
  • We do not share your data with advertisers.
  • We only share data with third parties to provide services you've requested.
  • You can export your data or delete your account at any time.

3. Data Access Control

We maintain strict internal controls to restrict access to user data. Access is only granted when necessary to provide support or services.

  • Role-based access control
  • Multi-factor authentication
  • Logged and audited access
  • Regular access reviews
  • Access revoked immediately upon termination

4. Authentication and Account Security

  • Secure password hashing
  • Multi-factor authentication (MFA)
  • Session timeout and management
  • Rate limiting and brute force protection
  • Automated alerts for suspicious login activity

5. Encryption

We use industry-standard encryption to protect your data both in transit and at rest.

6. Data in transit

All communications between your device and the platform are encrypted using Secure Sockets Layer (SSL) and Transport Layer Security (TLS).

7. Data at rest

Sensitive data is encrypted at rest using industry-standard AES-256 encryption. Encryption keys are managed using dedicated key management services.

8. Hosting Infrastructure

Our platform is hosted on Amazon Web Services (AWS), which provides a secure and resilient cloud infrastructure. We utilize several AWS security features, including:

  • Virtual Private Clouds (VPC)
  • Network Access Control Lists (NACL)
  • Security Groups
  • Web Application Firewalls (WAF)
  • Intrusion Detection Systems
  • DDoS protection

9. System Monitoring

We monitor our systems around the clock for performance, availability, and security.

  • Real-time logging and alerting
  • Security event monitoring
  • Vulnerability scanning
  • Performance monitoring
  • Uptime monitoring

10. Data Backups

We perform regular backups of our data to ensure availability and recoverability.

  • Daily backups
  • Backups are encrypted and stored in multiple locations for redundancy.
  • Regular testing of restore procedures.

11. Personnel Practices and Background Checks

We conduct background checks on all employees and contractors, subject to local laws and regulations.

Team members receive security training and are required to follow confidentiality agreements and internal security policies.

12. Internal Systems and Security

We maintain secure internal systems to support our operations.

  • Centralized identity and access management
  • Secure endpoint management
  • Regular patching and updates
  • Network segmentation
  • Malware protection

13. Subprocessors and Service Providers

We work with third-party service providers to help us deliver our services. These partners are selected for their commitment to security and privacy.

  • Financial data aggregators (e.g., Plaid, MX, Finicity)
  • Cloud infrastructure providers (e.g., AWS)
  • Email and communication services
  • Analytics and logging tools
  • Customer support tools
  • Payment processors

14. Incident Response

In the event of a security incident, we have an incident response plan in place to mitigate the impact and notify affected users.

  • Incident identification and categorization
  • Containment and eradication
  • Recovery and post-incident analysis
  • Notification as required by law

15. Product Governance

We follow secure software development lifecycle (SDLC) practices.

  • Code reviews for all changes
  • Automated security testing in CI/CD pipeline
  • Regular penetration testing by third-party security firms
  • Bug bounty program

16. Shared Responsibility

Security is a shared responsibility between Nonprofit Budget Builder and our users.

  • Use a strong, unique password
  • Enable multi-factor authentication
  • Be cautious of phishing attempts
  • Keep your devices and software up to date

17. Continuous Improvement

We are committed to continuously improving our security posture and adapting to the evolving threat landscape.

18. Questions?

If you have any questions or concerns about our security practices, please contact us:

  • Visit our Help Center
  • Contact our support team at support@nonprofitbudgetbuilder.com
  • Report a security vulnerability at security@nonprofitbudgetbuilder.com