Security is part of shipping, not a later version
Donation sites are a target for card-testing fraud and for anyone who wants a list of generous people. Here is what DuoGive does about it, in plain terms.
- Card data
- Card numbers are entered into your payment processor's hosted fields and never pass through DuoGive. We store the processor's transaction reference, the last four digits, and nothing else about the card.
- Card-testing attacks
- Checkout is rate-limited per address, per card fingerprint, and per account, with velocity thresholds that block the small-rapid-charge pattern fraudsters use to validate stolen cards. Repeated declines lock checkout for that source.
- Bots
- Public forms are protected with Cloudflare Turnstile. Verification fails closed: if the check can't complete, the submission is rejected rather than let through.
- Authorization
- Every request is authorized on the server. Donors can only reach their own records; staff roles are enforced per endpoint, not in the browser. Sensitive donor fields are locked behind feature flags that staff can't bypass from the UI.
- Account safety
- Login, password reset, and verification responses never reveal whether an email is registered. Reset links are single-use and expire. Super admins can reset a password or send a link, and both actions are logged.
- Audit log
- Matches, forwards, refunds, edits, exports, and admin tooling are recorded with the actor, the time, and the before/after where relevant.
- Backups
- The database is backed up hourly to separate object storage. A watchdog alerts if a backup is missed. The restore procedure is written down and has been exercised.
- Secrets
- API keys and signing secrets live in the hosting platform's encrypted secret store, never in the codebase or the browser. Keys are rotated if exposure is suspected.
- Transport and headers
- TLS everywhere with HSTS. Strict content-security, frame, and referrer policies. Error messages are generic and never include stack traces or schema details.
- Where data lives
- On Cloudflare's network, with the database and backups in the United States. Payment data lives with your processor under your agreement with them.
- Review
- Each release passes a security checklist and an automated scan before it deploys. Findings are fixed before launch, not filed for later.
Reporting a vulnerability
If you've found something, email security@duogive.com. We'll acknowledge within two business days and keep you updated until it's resolved. Please don't test against live donation flows with real cards.
Questions from your board or auditor
We're happy to walk through architecture, data flows, and controls in detail. Book time and mention security review in the notes.