Secure by design
DonorAtlas is SOC 2 Type II and HIPAA compliant, with enterprise-grade security built into every layer of the platform.
Enterprise-grade security
The controls behind each of these are independently audited and monitored continuously.
Data encryption
Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). That covers donor profiles, your uploads, and everything in between.
Single sign-on & SCIM
DonorAtlas integrates with SAML and OIDC providers including Okta, Azure AD, and Google. SCIM supports automated provisioning and deprovisioning.
Role-based access
Permissions are role-based and scoped to your team. Internally, access follows least privilege and is reviewed regularly.
Infrastructure security
DonorAtlas is hosted on AWS and Vercel in the United States. Production environments are isolated from development, and every change is peer-reviewed before it ships.
Continuous compliance
Security controls are monitored continuously — not checked once a year. Their live status is published in our Trust Center.
Monitoring & incident response
Production systems are logged and monitored around the clock, with alerting and an incident response plan for anything that needs attention.
Your data is not used to train models
We do not use your organization's data — contacts, uploads, or research — to train AI models, and our AI providers are contractually prohibited from doing so.
Two kinds of data. One standard of care.
Public records, cited to the source
Donor profiles are built from public sources — IRS nonprofit filings, campaign finance records, SEC filings, property records, and news. Every fact links back to where it came from.
- Built on public records
- Cited on every profile
Imported by you, visible only to you
The data your organization imports into DonorAtlas — contacts, files, research notes — is confidential customer data. It is encrypted, visible only to your team, and never mixed into anyone else's results.
- Never sold or shared
- Never used to train AI models
Common questions
Is DonorAtlas SOC 2 compliant?
Is DonorAtlas HIPAA compliant?
Where is my data stored?
Is my data used to train AI models?
Who can see my data?
How do I report a security issue?
Can you complete our security questionnaire or sign a DPA?
Want the full picture?
Compliance reports, policies, subprocessors, and the live status of our controls — all in one place.