Funraise prioritizes the security of data and payments with the highest level of data security, world-class infrastructure partners, and independent certification processes.
PCI Level 1 Certified
Funraise is a PCI Level 1 certified service provider, the highest standard possible for payment processing service providers. Funraise is partnered with Sikich as our QSA and independent security assessor.
Data Security
Funraise is deployed to Amazon Web Service (AWS). Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon’s data center operations have been accredited under:
Additionally, all Funraise data is managed in a premium Postgres cluster with hot standby which benefits from geo-redundancy, point-in-time recovery, priority service restoration on disruptions, and automatic encryption-at-rest of all data written to disk.
Funraise employs modern ciphers and hashing algorithms for data encryption and password hashing. Communications to and from Funraise servers are encrypted by TLS 1.2+.
OWASP
Funraise coding guidelines are integrated with OWASP best practices. These practices are enforced through static code analysis and peer review of every change made to the Funraise codebase. Funraise also employs a dedicated QA team as well as independent security specialists that test our software for bugs and potential vulnerabilities.