Names, capacity estimates, giving history, private notes about people who trust your organization. We built ChaiRaise on the assumption that this data should never be casually exposed, resold, mined, or held hostage. This page describes exactly how it is protected — and every claim here is something we actually implemented.
Every record is scoped to your organization, and every data request is checked against your membership before a single row is returned. An org id is not a password: if you are not a member of an organization, the API refuses the request outright. There is no shared donor pool and no cross-tenant read path.
AI features run through one authenticated server endpoint. Our AI provider key lives on the server and is never shipped to your browser, and donor details are never posted from your device to a third party. That path is auditable, rate-limited and sits entirely inside our boundary.
Connect your own email (Gmail, Outlook, or any provider) and outreach is relayed through YOUR mail server, from YOUR address. We do not keep a copy of your mailbox. Your SMTP password is encrypted with AES-256-GCM before it is stored and is never returned by our API — not even to you.
WhatsApp outreach uses click-to-chat links that open your own WhatsApp with the message pre-filled. We hold no WhatsApp session and proxy no messages, so donor phone numbers and message content never pass through our servers on the way to Meta.
One click exports every record we hold for your organization — donors, gifts, activities, pipeline, campaigns and your full audit trail — as a single JSON file. No support ticket, no export fee, no lock-in. Credentials are deliberately excluded from exports.
You can permanently erase an individual donor or your entire organization. Deletion is a hard delete across every table, not a hidden flag on a row we quietly keep. It is irreversible by design and requires typed confirmation.
What a security reviewer on your board will want itemized.
The complete list of subprocessors. We do not sell donor data, we do not share it with advertisers, and we do not use your donor records to train models.
We would rather be trusted than impressive. ChaiRaise is a young product: we do not hold a SOC 2 report or an ISO certification, and we have not commissioned a third-party penetration test. We will say so plainly here until that changes, rather than imply coverage we do not have. If your organization requires a formal security review or a signed data processing agreement, contact us and we will work through it with you directly.
Report it to security@chairaise.com. We will acknowledge responsible disclosures and will not pursue action against good-faith researchers.