← Pay It Forward OS

TRUST & SECURITY

Security Overview

1. Organization separation

Each participating organization operates in its own organization-scoped environment. Content and operational records are tied to that organization rather than blended into a shared public pool with other nonprofits.

2. Role-based access

Access inside a workspace depends on membership and role. Admins, members, and other approved roles receive different levels of access based on what they need to do.

3. Sensitive CRM permission controls

Supporter and relationship records can require an additional permission rather than being visible to every organization member by default.

4. Authentication and login history

Workspace access uses authenticated accounts. Organizations should name an accountable point of contact and keep member access current as people join or leave the team.

5. Database-level access controls

Platform data access is enforced with organization scoping and database policies so one organization's private records are not treated as another organization's data. This overview deliberately omits internal infrastructure details.

6. File-storage scoping

Files and documents attached to an organization are intended to stay within that organization's workspace rather than appearing in another nonprofit's account.

7. Payment status

Donation tracking and fundraising records are built into PIFOS. Live on-site card processing is currently turned off and remains in final testing. When activated, PIFOS will take 0% of charitable donations. Standard third-party processor costs may still apply.

8. Responsible security contact

Report suspected security issues to hello@payitforwardos.com. Please include enough detail for us to investigate without sharing secrets in public channels.

9. No absolute security promise

No software system can promise absolute security. We design for separation, least privilege, and honest disclosure of known limits—and we take reported issues seriously.

Questions? hello@payitforwardos.com