Security & Trust Center

How FundlyHub protects accounts, payments and data, and what we check automatically.

Some checks are not passingLast check: 8 min ago

Checked automatically

A monitor runs these checks every 10 minutes. Each row shows when it last passed.

  • Payment processing connected (Stripe)Passed 8 min ago
  • Sign-in service configured (AWS Cognito)Passed 8 min ago
  • Databases healthyPassed 8 min ago
  • Access roles and permissions in placePassed 8 min ago
  • Error monitoring reachable (Sentry)Not passing

How we protect your data

Practices in place today.

  • Card data stays with Stripe

    Card details go straight to Stripe, a PCI DSS Level 1 service provider. FundlyHub does not store card numbers.

  • Encrypted connections

    Your connection to fundlyhub.org and to our API uses HTTPS.

  • Sign-in

    Accounts sign in through AWS Cognito, with Google and Apple sign-in available. Session tokens are kept in httpOnly cookies, not in browser storage.

  • Staff access

    Admin tools are limited by role, and admin changes are written to an audit log.

  • Abuse protection

    Sign-in and API requests are rate limited.

In progress

Listed here until we can show evidence for them.

  • Two-factor authentication for user accountsComing soon

Documents

Our security practices, vendor transparency, and incident response process.

Request security documentation

Need more details for your security review or vendor assessment? We're happy to provide additional documentation.

Last updated: October 2026

Connecting causes with caring people worldwide

FundlyHub is a DBA ofCYTY Inc.CYTY Inc.

For Fundraisers

Start a CampaignSuccess StoriesResources

© 2026 CYTY Inc. (DBA FundlyHub). All rights reserved.

Privacy PolicyTerms of Service