Our Approach to Security
Protecting the data that fundraising organizations and their donors entrust to us is fundamental to how we build Sapling CRM and Sapling Pay. We maintain administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction. This page summarizes those safeguards. The binding, detailed commitments live in our Data Processing Agreements.
Encryption
- In transit: Data is encrypted in transit using TLS 1.2 or higher.
- At rest: Data is encrypted at rest using AES-256 or an equivalent standard, where commercially reasonable.
Payment Security (Sapling Pay)
- Donor card details are entered directly into our payment partner’s hosted payment fields (Stripe Elements). Full card numbers, CVV/CVC codes, and bank credentials are transmitted directly to Stripe and do not traverse or reside on our systems.
- We do not store full payment card numbers, CVV/CVC codes, or bank credentials. We retain only payment tokens and, at most, truncated display data (card brand and last four digits).
- Sapling Pay validates under PCI DSS SAQ A (the self-assessment questionnaire for a fully outsourced card-data integration) and maintains its attestation on the basis of Stripe’s PCI DSS Level 1 certification, the highest level of payment-industry compliance.
- Sapling Pay is not a bank; funds are held and settled by Stripe under the Stripe Connected Account Agreement.
Access Controls
- Role-based access controls limit access to personal data to personnel with a documented business need.
- Least-privilege permissions are enforced at the application and infrastructure levels.
- Multi-factor authentication is required for privileged access to production systems.
- Payment and token data is isolated per organization (row-level isolation), so one organization’s data is not accessible to another.
Monitoring and Logging
- We log and monitor access to production environments and to the personal data we process.
- We maintain access logs recording personnel access to that data — including the identity of the accessing individual, the category of data, the business purpose, and the timestamp — retained for at least twelve (12) months and available in connection with a confirmed or suspected security incident or regulatory inquiry.
Infrastructure and Subprocessors
- We host and operate on reputable, primarily U.S.-based cloud infrastructure providers.
- We impose data-protection obligations on the subprocessors we engage, consistent with our DPAs. The current, authoritative lists of subprocessors are maintained in the Sapling CRM DPA and the Sapling Pay DPA, which also describe how we notify customers of changes.
Vulnerability Management
We perform vulnerability management, including regular security scans and timely patching of critical vulnerabilities, and maintain malware protection on the systems we control.
Business Continuity and Disaster Recovery
We maintain documented disaster recovery and business continuity procedures, tested at least annually, and maintain backups designed to allow recovery of data in the event of a failure.
Incident Response
- We maintain documented incident response procedures with defined escalation paths and notification timelines.
- In the event of a security incident affecting customer or donor data, we notify affected customers without undue delay and, where feasible, within seventy-two (72) hours of confirmation, as set out in our DPAs.
- We work to confirm or rule out a suspected incident within forty-eight (48) hours of discovery.
Our People
- Personnel with access to personal data are bound by written confidentiality obligations and may access that data only as necessary to provide, maintain, support, or secure the services, investigate an incident, or meet legal obligations.
- Personnel receive periodic security awareness training.
AI Features
AI-assisted features (Orchid AI) use third-party AI providers as subprocessors. We use data in de-identified, aggregated form to improve our services and do not use identifiable customer data to train AI models without prior express written consent, and we do not use customer data to train generalized AI models for unrelated third-party commercial purposes. Customers may opt out of service-improvement processing. See the Sapling CRM DPA and our Privacy Policy.
Compliance and Privacy
Our processing of personal data is governed by our Data Processing Agreements and described in our Privacy Policy at saplingcrm.org/privacy-policy, including how individuals may exercise privacy rights under the CCPA/CPRA and GDPR.
Reporting a Security Concern
If you believe you have found a security vulnerability or have a security concern, please contact us at security@saplingcrm.org. We appreciate responsible disclosure and will work to investigate and address valid reports promptly.
Changes
We may update this Security Policy from time to time. Material changes will be reflected by updating the effective date below.
Questions about security? Contact security@saplingcrm.org.
Last edited: July 20, 2026.