Product

Security built for fundraising operations

Charity tenancy, signed partner webhooks, and a settlement model that never requires Donorgram to hold donor card data.

Zero-touch partner funds

When merchants collect round-ups, money stays with them until they settle with your charity via invoice.

HMAC-signed ingestion

Partner order logs are signature-verified so only authorised merchants can write to your ledger.

Charity-scoped access

Multi-tenant policies keep merchants, campaigns, and transactions isolated per organisation.

Rotatable keys

Rotate public widget keys when a partner leaves or a credential needs refreshing.

Transport security

API traffic is designed for HTTPS in production; secrets never ship in browser embeds.

Operational audit trail

Ledger statuses move clearly from logged → invoiced → paid for finance visibility.

Talk through security with our team

We can walk fundraising and IT stakeholders through the trust model in one session.