LIVE EVENTFrom the Field: Real-World Applications of DonorAtlas.

Secure by design

DonorAtlas is SOC 2 Type II and HIPAA compliant, with enterprise-grade security built into every layer of the platform.

Enterprise-grade security

The controls behind each of these are independently audited and monitored continuously.

Data encryption

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). That covers donor profiles, your uploads, and everything in between.

Single sign-on & SCIM

DonorAtlas integrates with SAML and OIDC providers including Okta, Azure AD, and Google. SCIM supports automated provisioning and deprovisioning.

Role-based access

Permissions are role-based and scoped to your team. Internally, access follows least privilege and is reviewed regularly.

Infrastructure security

DonorAtlas is hosted on AWS and Vercel in the United States. Production environments are isolated from development, and every change is peer-reviewed before it ships.

Continuous compliance

Security controls are monitored continuously — not checked once a year. Their live status is published in our Trust Center.

Monitoring & incident response

Production systems are logged and monitored around the clock, with alerting and an incident response plan for anything that needs attention.

Your data is not used to train models

We do not use your organization's data — contacts, uploads, or research — to train AI models, and our AI providers are contractually prohibited from doing so.

Never used for trainingNever soldNever shared

Two kinds of data. One standard of care.

Our data

Public records, cited to the source

Donor profiles are built from public sources — IRS nonprofit filings, campaign finance records, SEC filings, property records, and news. Every fact links back to where it came from.

  • Built on public records
  • Cited on every profile
Your data

Imported by you, visible only to you

The data your organization imports into DonorAtlas — contacts, files, research notes — is confidential customer data. It is encrypted, visible only to your team, and never mixed into anyone else's results.

  • Never sold or shared
  • Never used to train AI models

Common questions

Is DonorAtlas SOC 2 compliant?
Yes. DonorAtlas undergoes regular SOC 2 Type II audits by an independent firm. You can request the report and see the live status of our controls in our Trust Center.
Is DonorAtlas HIPAA compliant?
Yes. DonorAtlas is HIPAA compliant and operates as a Business Associate, and we are ready to sign a BAA with your organization.
Where is my data stored?
Customer data is stored in AWS data centers in the United States. It is encrypted at rest and does not leave the US.
Is my data used to train AI models?
No. We do not use your data to train AI models, and our AI providers are contractually prohibited from training on it. Your data is never sold or shared.
Who can see my data?
Only your team. Data you import into DonorAtlas is scoped to your organization and is never visible to other customers. Internal access is limited to the employees who need it to support you.
How do I report a security issue?
Email team@donoratlas.com with a description of the issue. We review every report, and we appreciate responsible disclosure.
Can you complete our security questionnaire or sign a DPA?
Yes. Policies, subprocessors, and compliance reports are available self-serve in the Trust Center. For questionnaires, DPAs, or anything else, email us and we'll turn it around quickly.

Want the full picture?

Compliance reports, policies, subprocessors, and the live status of our controls — all in one place.