Security & Compliance
Trusted with your most important data.
VolunteerReady handles sensitive information — background checks, personal records, organizational data. Here's exactly how we protect it.
How we protect your data
Security isn't a feature we added — it's how the platform was designed from day one.
Encryption at rest and in transit
All data is encrypted in transit with TLS 1.3 and at rest using AES-256. The credentials we hold to reach a background check provider on your behalf — Checkr OAuth tokens and Sterling API keys alike — are additionally encrypted with application-level encryption before storage.
FCRA-compliant background checks
The full adverse action workflow required by the Fair Credit Reporting Act — pre-adverse notice, waiting period, and final adverse action — lives in the platform, not in one vendor integration, so it runs the same whether your checks go through Checkr or Sterling. Organizations stay compliant without legal expertise.
Multi-tenant data isolation
Every database query is scoped to the requesting organization. Volunteers see only their own data. Organizations cannot access each other's applicant pools, screening results, or credentials.
Role-based access control
Four roles — owner, admin, staff, and read-only — each inheriting only what the one below it has. Promoting someone to admin is reserved to owners, enforced in the service rather than by hiding the button. Every role change and permission grant is logged.
Audit logging
Every significant action — application approvals, credential issuance, background check requests, team changes — is logged with timestamps, attribution, and before/after state.
Volunteer-controlled access revocation
Volunteers can revoke any single organization's access to them from their profile, instantly and without asking us. That organization can no longer open their volunteer record, schedule them, or request a background check — and it cannot undo the revocation or re-add them. Only the volunteer can restore the relationship. Two documented limits: a profile set to Public stays publicly visible until the volunteer changes that, and a volunteer who is also staff at that organization keeps their staff access.
Data portability
Your volunteer roster exports to CSV on every plan, Free included — an org that cannot get its data back out has not really chosen to stay, so we refuse to make the exit a paid feature. The roster itself is rolling out organization by organization; wherever it is switched on, the export comes with it at no cost. Volunteers own their portable credentials outright. If you leave the platform, your data leaves with you.
Compliance and data governance
FCRA (Fair Credit Reporting Act)
Full adverse action workflow for background checks: pre-adverse notice, mandatory waiting period, and final adverse action notice. Built into the screening flow — not an afterthought.
Soft delete and data retention
Records are soft-deleted, not permanently removed, ensuring audit trail integrity. Data retention policies align with legal requirements for employment and volunteer screening records.
Credential verification chain
Every portable credential tracks which organization issued it, when, and the evidence behind it. Credentials can be revoked with a full audit trail of the revocation.
Secure authentication
Authentication powered by NextAuth with the Prisma adapter, via emailed magic links or Google sign-in. Session management follows OWASP best practices. We store no passwords at all — there is nothing to leak, reuse, or phish.
Our commitment
We know that nonprofits trust us with sensitive volunteer data, and volunteers trust us with their personal information. That trust is the foundation of everything we build. If you have questions about our security practices or need documentation for your compliance review, reach out — we're happy to help.
Ready to get started?
Create a free account backed by enterprise-grade security. No credit card required.