Trust

Security

Payments are mission-critical. The platform is built to keep card data out of our systems and gifts isolated by organization.

PCI scope

Card details are entered in Stripe.js / Payment Element. DonorForward stores payment intent identifiers and statuses, never PAN or CVC.

Access control

JWT bearer tokens, role checks on every mutation, and organizationId scoping in services — not only in the UI.

Reliability

Webhooks are signed and idempotent. Receipt email is asynchronous. A mail failure cannot reverse a successful charge.

Audit

Sensitive changes (payment configuration, organization settings) write an audit record: who, what, when.