1. Organization separation
Each participating organization operates in its own organization-scoped environment. Content and operational records are tied to that organization rather than blended into a shared public pool with other nonprofits.
2. Role-based access
Access inside a workspace depends on membership and role. Admins, members, and other approved roles receive different levels of access based on what they need to do.
3. Sensitive CRM permission controls
Supporter and relationship records can require an additional permission rather than being visible to every organization member by default.
4. Authentication and login history
Workspace access uses authenticated accounts. Organizations should name an accountable point of contact and keep member access current as people join or leave the team.
5. Database-level access controls
Platform data access is enforced with organization scoping and database policies so one organization's private records are not treated as another organization's data. This overview deliberately omits internal infrastructure details.
6. File-storage scoping
Files and documents attached to an organization are intended to stay within that organization's workspace rather than appearing in another nonprofit's account.
7. Payment status
Donation tracking and fundraising records are built into PIFOS. Live on-site card processing is currently turned off and remains in final testing. When activated, PIFOS will take 0% of charitable donations. Standard third-party processor costs may still apply.
8. Responsible security contact
Report suspected security issues to hello@payitforwardos.com. Please include enough detail for us to investigate without sharing secrets in public channels.
9. No absolute security promise
No software system can promise absolute security. We design for separation, least privilege, and honest disclosure of known limits—and we take reported issues seriously.