Security & Trust

How we protect your organization's data

Inspire Generosity is built on the same infrastructure providers used by companies with dedicated security teams — not built from scratch. This page explains exactly what that means, provider by provider, including where we still have room to grow.

Last reviewed: August 2026
🔐

Identity & Access

Provided by Clerk
☁️

Infrastructure

Provided by Cloudflare
🗂️

Source Control & Change Management

Provided by GitHub
🛡️

What We've Built

Application-level, our own code
💳

Payment Data

📋

Where We're Still Maturing

We'd rather tell you what's not done yet than let you assume it is. None of the items below are hidden from our own team — they're on our roadmap, not swept under a rug.

Honestly, not yet in place

  • No independent SOC 2 or ISO 27001 certification of Inspire Generosity itself — our infrastructure providers (Clerk, Cloudflare) are certified; we have not yet completed our own third-party audit.
  • No formal third-party penetration test of the application has been conducted yet.
  • Branch-protection rules and GitHub secret scanning are not yet enabled on our repository — both require a plan upgrade we haven't completed.
  • No public bug bounty or coordinated disclosure program yet — see below for how to report a concern in the meantime.
  • No published data retention or deletion policy yet — reach out directly if this is a blocker for your review.

Reviewing this for procurement?

Email us directly — we'll answer specific questions a standard security questionnaire doesn't cover, and tell you plainly if something isn't ready yet.

Contact Us