VolunteerFlow
HomeFeaturesHow it worksPricingAboutOrganizations
Start free

Security

Last Updated: September 24, 2026

This is a summary. The measures below are contractual commitments set out in Annex A of our Data Processing Agreement, which forms part of our Terms of Service for every organization. If this page and Annex A differ, Annex A controls.

Signing in and access

  • Passwords are stored only as bcrypt hashes, and repeated failed sign-ins lock the account for a while.
  • Every staff account can turn on multi-factor authentication with an authenticator app or an emailed code. On the Impact plan, admins can stop users from turning it off.
  • Your organization decides who sees what with roles and permissions. Health and medical records need an explicit permission, even for admins.
  • On the Impact plan, you can limit staff access to your own IP addresses.
  • Sessions are checked on every request, you can see and end your own sessions, and the web app signs staff out after 30 minutes of inactivity.

Encryption

  • All traffic is encrypted with TLS, and browsers are told to use HTTPS only.
  • The database and file storage are encrypted at rest.
  • Health and medical records, government ID references, and locked case notes get a second layer of encryption from VolunteerFlow, with keys specific to your organization.

Keeping organizations apart

  • Every request is limited to your organization, and location restrictions you set are enforced on our servers.
  • An automated check on every code change blocks database queries that are missing that organization limit.

Logging

  • Sign-ins and administrative changes are logged.
  • If VolunteerFlow support ever opens your account to help you, the session is logged and shown to you in your security settings.

How we build

  • Every code change is scanned automatically for leaked secrets and known vulnerable dependencies, and the whole codebase is re-scanned weekly.
  • Uploaded files are checked by their real content, not just their file name.
  • Webhooks can only be sent to public HTTPS addresses.

Backups and deleting data

  • The database is backed up daily, and backups expire within 30 days.
  • When an organization leaves, it can export its data for 30 days. We delete it from our systems within the next 60 days, and it expires from backups within 30 days after that.

If something goes wrong

If a breach affects your organization's data, we tell your administrators without undue delay and no later than 72 hours after we discover it.

Certifications and questionnaires

We don't yet hold a third-party certification such as SOC 2. We answer security questionnaires, and once a year we will share the information needed to show we meet our Data Processing Agreement.

Contact

Security questions, questionnaires, or a vulnerability to report: legal@volunteerflow.us.

VolunteerFlow

The volunteer management platform built for organizations that want to make a bigger impact.

Disabled Military Veteran-Owned Business
Product
How it worksFeaturesPricing
Company
AboutCareersContact
Legal
Privacy PolicyTerms of ServiceAcceptable UseCookie PolicyBilling & RefundsData ProcessingSecurity

© 2026 VolunteerFlow. All rights reserved.

Status