Security & compliance
Donor data and HMRC credentials, properly protected
Gift Aid means handling sensitive personal and financial data on behalf of your donors. Hereβs how we keep it safe β and keep you audit-ready.
Encrypted Government Gateway credentials
Your HMRC sign-in is encrypted with AES-256-GCM and stored write-only β it's used to submit the claims you initiate and is never displayed back to anyone, including our own staff.
Per-charity data isolation
Every charity is a separate tenant, enforced at the database level with row-level security. A query can't return another charity's data even if application code has a bug.
Built on HMRC's official schema
Claims are validated against HMRC's own current schema before anything is sent. Invalid claims are rejected locally β they never reach HMRC.
Audit-grade declaration records
Every declaration is captured with a timestamp and the method of capture β the auditable record of the making of the declaration that HMRC's regulations require.
Cyber Essentials
We are working towards Cyber Essentials certification, the UK government-backed baseline every serious Gift Aid supplier holds.
Data portability & retention
Your data is yours. Export donors, declarations and a full audit log as CSV at any time, and keep the six years of records HMRC requires β without paying more to store them.
A quick note on honesty
We mark certifications as 'in progress' where they are. We'd rather tell you exactly where we stand than display a badge we haven't earned yet. If a specific compliance question matters to your board, ask us β we'll give you a straight answer.
Have a security or DPO question?
We're happy to walk your board or data-protection officer through how the platform handles donor data.