Skip to main content
Security & Data Protection

Security practices built for sensitive nonprofit data.

We implement industry-standard security practices to protect your organization's data. Here is an honest overview of the measures we have in place today.

Our Security Commitment

As a platform trusted by nonprofits to manage sensitive program and participant data, we understand the responsibility that comes with that trust. We are committed to protecting your information with robust, transparent security practices.

We believe in being straightforward about what we do and where we are headed. Below you will find an honest description of our current security measures and our roadmap for formal compliance certifications.

Current Security Practices

Encryption in Transit

Data transmitted between supported browsers and Instrumento’s services is encrypted in transit using TLS/HTTPS. Encryption helps reduce the risk of unauthorized interception while data is being transmitted.

Secure Authentication

You can sign in with Google, or with an email address and password. Passwords are not stored in plaintext. Password-based accounts use Argon2id hashing, and sessions are managed using signed, HTTP-only cookies designed to limit access from client-side scripts.

Managed Cloud Infrastructure

Our application runs on managed cloud infrastructure with automatic scaling, redundancy, and regular backups. The database is hosted on TiDB, a distributed SQL platform with built-in high availability.

Role-Based Access Control

Organizations can manage team members with role-based permissions. Only authorized users within your organization can access your data. API keys and secrets are stored securely and never exposed to the client.

PCI-Compliant Payments

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store, process, or have access to your credit card numbers or payment details.

Cloud-Hosted Data Storage

Your data is stored on cloud infrastructure provided by reputable providers. Uploaded files are stored in Cloudflare R2, in Cloudflare's Eastern North America region. We are evaluating data residency options for organizations with specific geographic requirements.

Your Data Belongs to You

We believe your data is your property. You maintain full ownership and control over all information you enter into Instrumento. We do not sell, share, or use your data for advertising purposes.

You can export your data at any time through our dashboard export features. You can request deletion of your individual account at any time; deletion of an organization's data is an organization-level action, carried out under your organization's agreement with us.

Our Data Promise

  • Your data is never sold to third parties
  • Your data is never used for advertising
  • You can export your data at any time
  • You can request deletion of your individual account; organization data deletion follows your organization's agreement

Our Compliance Roadmap

We are actively working toward formal security certifications. While we do not hold these certifications today, here is our planned path forward.

01

Current: Security Best Practices

Implementing and documenting industry-standard security controls, encryption, access management, and incident response procedures.

02

Next: SOC 2 Type I

Working toward a point-in-time assessment of our security controls by an independent auditor, validating our security posture.

03

Future: SOC 2 Type II

Pursuing continuous compliance certification that demonstrates our security controls are effective over an extended review period.

Have Security Questions?

We are happy to discuss our security practices in detail and provide additional documentation for your organization's review process.