Security & Trust Center
How FundlyHub protects accounts, payments and data, and what we check automatically.
Checked automatically
A monitor runs these checks every 10 minutes. Each row shows when it last passed.
- Payment processing connected (Stripe)Passed 8 min ago
- Sign-in service configured (AWS Cognito)Passed 8 min ago
- Databases healthyPassed 8 min ago
- Access roles and permissions in placePassed 8 min ago
- Error monitoring reachable (Sentry)Not passing
How we protect your data
Practices in place today.
Card data stays with Stripe
Card details go straight to Stripe, a PCI DSS Level 1 service provider. FundlyHub does not store card numbers.
Encrypted connections
Your connection to fundlyhub.org and to our API uses HTTPS.
Sign-in
Accounts sign in through AWS Cognito, with Google and Apple sign-in available. Session tokens are kept in httpOnly cookies, not in browser storage.
Staff access
Admin tools are limited by role, and admin changes are written to an audit log.
Abuse protection
Sign-in and API requests are rate limited.
In progress
Listed here until we can show evidence for them.
- Two-factor authentication for user accounts
Documents
Our security practices, vendor transparency, and incident response process.
Request security documentation
Need more details for your security review or vendor assessment? We're happy to provide additional documentation.
Last updated: October 2026