Security
Security & compliance posture
Fundly is a fundraising platform for K-12 schools, PTAs, and youth organizations. This page is a public, plain-language summary of the controls we operate today and the certifications and reviews on our public roadmap. It is written for district IT, school board treasurers, and procurement reviewers evaluating Fundly.
Published commitments
These are the security milestones we have told the public we are working toward. Dates are commitments, not guarantees; we update this page as dates firm up or change.
Annual external pentest
We commission an external penetration test at least once a year from an independent third-party firm. Next target: Q2 2027. A high-level summary of scope and findings will be linked from this page after each test.
SOC 2 Type 1
We are working toward a SOC 2 Type 1 report covering the Fundly web app and API. Target: Q4 2027. This is a commitment, not a guarantee: actual timing depends on auditor availability and any remediation work surfaced during readiness.
Quarterly restore drills
Backups are exercised, not just taken. A restore drill runs once per quarter, in the first 30 days of the quarter, against a scratch target. Results are logged with row counts and elapsed time.
How we handle your data
Procurement reviewers should pair this section with our Privacy Policy, which is the authoritative document.
Money path
All donations and sale proceeds are processed by Stripe Connect and deposited directly to each organization’s connected Stripe account. Fundly does not hold, route, or escrow customer funds. Card data is handled by Stripe and never touches our servers.
Encryption
Data is encrypted in transit using TLS 1.2+ on every production endpoint. Application databases are encrypted at rest using the platform-managed disk encryption provided by our infrastructure vendor.
Account access
Authenticated access to organization and campaign data is gated by single-factor email magic links, with an optional TOTP second factor for admins and advisors. Admin resets of another user’s authenticator are rate-limited and audit-logged.
Operational practices
- Change management. Production changes go through code review and a deploy checklist; infrastructure changes are documented in the ops runbook.
- Audit log. Sensitive administrative actions (campaign launch, admin reset, delegate-approver grant, payout config changes) are written to an append-only audit event stream visible to org admins.
- Backups. Nightly database snapshots are retained; the quarterly restore drill (§2 of the ops runbook) proves they are restorable end-to-end.
- Incident response. An internal runbook defines severity levels, who notifies whom, what goes on the status page, and when affected organizations are emailed. The runbook is reviewed quarterly.
- Least privilege. Staff access to production data is limited to what is needed to do the job, with production access gated by team-internal procedures.
Report a vulnerability
We welcome reports from security researchers and from the procurement and IT teams evaluating Fundly. See our Vulnerability Disclosure Policy for scope, the responsible-disclosure process, our acknowledgment window, and the 90-day coordinated-disclosure target.
The canonical contact is [email protected]. A machine-readable copy of our disclosure contact and policy is published at /.well-known/security.txt per RFC 9116.
Acknowledgments
With researcher permission, we acknowledge reporters of valid vulnerabilities on this page after the issue is fixed and the coordinated-disclosure window has elapsed. This list is empty today; it will be updated as reports come in.