Koolay hosts sensitive nonprofit data โ donor records, payment history, member PII, scholarship applications, user accounts. This page summarizes how we protect it.
Certifications and compliance
SOC 2 Type II
๐ก Readiness phase โ target report Q3 2026
GDPR
โ DPA on file, EU SCCs executed, self-service data export and deletion
CCPA / CPRA
โ Honored; Koolay does not sell personal information
PCI DSS
โ All card data handled by Stripe (PCI Level 1); we never see card numbers
HIPAA
โช Not required โ we do not process health data
Subprocessor certifications we rely on: Supabase SOC 2 Type II, Vercel SOC 2 Type II, Stripe PCI DSS Level 1 / SOC 1/2, AWS SOC 1/2/3 and ISO 27001.
Infrastructure
Hosting: Supabase on AWS US-East-1 (primary), Vercel global edge CDN
Encryption at rest: AES-256 (Supabase managed keys + encrypted secrets vault via pgcrypto)
Encryption in transit: TLS 1.2+ everywhere (HSTS enabled)
Tenant isolation: Row-Level Security (RLS) on every multi-tenant table
Principle of least privilege: service role keys scoped narrowly; admin access role-based per tenant
Quarterly access reviews: staff and subprocessor credentials reviewed each calendar quarter
Audit logging: every mutation on sensitive tables (donations, donors, memberships, scholarship applications, user roles, volunteers, contact submissions, newsletter subscribers, event raffle tickets, donor stewardship) is recorded with actor, timestamp, and before/after state (with PII redacted). Admins can review at Admin โ Settings โ Audit Log.
Data handling
Customer Data is segregated by tenant via RLS. Tenants cannot read each other's data.
Customer Data is never used for AI model training. OpenAI and Anthropic operate under zero-retention agreements for API usage.
Self-service data export: Admin โ Settings โ GDPR โ Export