Product Areas
All Products
CyberGrants
NGP VAN
Apricot/ETO
EveryAction
OneCause
DonorDrive
Network for Good
Start your security review
View & download sensitive information
Bonterra Strategic Philanthropy helps increase employee engagement and streamline grants management in a cohesive corporate giving platform. In support of Bonterra's strong commitment to compliance and third-party risk management, we are pleased to provide our valued partners seamless access to our Information Security assurance reporting.
This transparency allows our partners to reduce friction during 3rd party auditing reporting requests and increases transparency to our current security posture.
Data Access Level
4Impact Level
4Recovery Time Objective
5Multi-Factor Authentication
5Product Architecture
5Role-Based Access Control
4Network Diagram
3PCI DSS
4PCI DSS 4.0.1
1Other Self-Assessments
1Data Backups
5Encryption-at-rest
5Encryption-in-transit
5Application Penetration Testing
5Code Analysis
5Credential Management
5AI Monitoring
1AI Risk Management
1AI Governance
1Anti-Bribery and Corruption
4Anti-Competitive Practices
4Code of Ethics
4Subprocessors
4Cyber Insurance
4Data Processing Agreement
4Cookies
4Data Breach Notifications
2Data Out of System
4Data Access
2Logging
4Password Security
5Status Monitoring
5Amazon Web Services
5Anti-DDoS
5Disk Encryption
5Endpoint Detection & Response
5Threat Detection
5Firewall
1IDS/IPS
1Security Information and Event Management
1We implement internal measures and practices to maintain a high standard of security.
We are currently working with experts to put together our company policies. Please contact us for more details.
BitSight
5Security Headers
3We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.
We provide security awareness training to all employees to ensure that they are aware of security best practices.
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
We have physical and environmental controls in place to ensure that our data centers are secure and reliable.
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.




