Third Party Index

Snapshot 66729

Document
Security page
URL
https://help.givecloud.com/en/articles/6045181-security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
86125 bytes
SHA-256 (raw)
c8da2aa307284f7ee0d19e61d04e062be7017940bfbc6e0823a44036f0c9d707
SHA-256 (normalized text)
652d13e32f57db867fb2596e2cc4971e2f4ef4e6b4ff648d3cc6aee50fa30e04

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Copyright (c) 2023, Intercom, Inc. (legal@intercom.io) with Reserved Font Name "Poppins". This Font Software is licensed under the SIL Open Font License, Version 1.1.Copyright (c) 2023, Intercom, Inc. (legal@intercom.io) with Reserved Font Name "Inter". This Font Software is licensed under the SIL Open Font License, Version 1.1.Skip to main content
Security
Givecloud Security Statement
April 11, 2024
Table of contents
Last update: April 11, 2024
Security Statement
Givecloud prioritizes cybersecurity to shield against external threats and internal risks. We have established suitable management, operational, and technical controls to mitigate cyber risks, bolster resilience against cyber incidents, and safeguard against cyber threats. Complying with or surpassing the industry’s information security best practices, Givecloud implements robust security measures to defend its clients and itself.
Givecloud is SOC 2 Type 2 audited, demonstrating our organization’s secure handling of your confidential data.
Givecloud's payment partners are PCI DSS compliant, ensuring that all financial transactions are safe and secure.
Givecloud utilizes TLS version 1.3 with 256-bit encryption, guaranteeing the highest levels of confidentiality, integrity, and privacy for all information exchanged between Givecloud and its customers.
Givecloud’s service resides in a world-class data center that has passed over 20 audits and assessments by 3rd-party security assessors.
Givecloud's cybersecurity program is aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). This page offers a comprehensive overview of Givecloud's information security strategy and outlines our practices for securing information, systems, and services. Our approach is organized according to the five core functions of the NIST CSF:
Identify
❖ Risk Governance
Risk governance and risk management are a function of Givecloud’s management culture. Givecloud’s governance model is achieved by the day-to-day activities of managers and their teams.
❖ Asset Management
Givecloud maintains an asset management system that inventories, classifies, and protects applications, information, and hardware. Givecloud’s Mobile device management implementation allows it to control, secure and enforce policies on smartphones, tablets, and other endpoints.
Protect
❖ Identity and Access Management
Givecloud has implemented security controls to identify, authorize, authenticate and manage individuals’ access to Givecloud’s systems and information assets.
❖ Applications and Software Security
Givecloud manages application and software security through its secure software development practices, vulnerability testing, monitoring, and logging.
❖ Infrastructure Security
Givecloud protects its infrastructure through vulnerability testing, system hardening, and malware protection.
❖ Data Protection and Data Privacy
Givecloud has implemented security controls that are designed to safeguard Givecloud and client data. This includes the secure storage and transmission of data.
❖ Mobile Security
Givecloud’s mobile solutions allow employees to conduct business activities on their personal devices while protecting Givecloud systems and client information.
❖ Physical Security
Givecloud has implemented physical security controls at all Givecloud facilities including its office spaces, and cloud-based facilities.
Detect
❖ Continuous Monitoring
Givecloud maintains detective security controls at the network, end-point, and application layers to detect anomalous activities, potential threat activities, and indicators of compromise.
❖ Anomaly Detection
Givecloud has deployed end-point protection and detection services to ensure that security anomalies and events are detected quickly, and their potential impact is understood.
Respond
❖ Incident Management
Givecloud’s incident management processes enable the effective detection and management of security threats and incidents that have the potential to impact the confidentiality, integrity, or availability of Givecloud’s information, applications, and services.
For more information, see Givecloud's Trust Center.
Recover
❖ Givecloud’s Business Continuity and Disaster Recovery processes covers both business and technology resilience. Givecloud’s cloud-based infrastructure features a highly available architecture where applications and information can be restored within their Recovery Time Objective.
←Back to main site
Related Articles
GDPR and Givecloud
Security Measures for Carding Bots & Preventing Fraud
How to Manage Your Givecloud Billing Information
How does Givecloud manage high traffic/donation volume?
How Givecloud Leverages OFAC Sanctions List
Did this answer your question?
Table of contents