SOC2C

Is this your company? Buyers are checking Double the Donation here. Claim doublethedonation.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Double the Donation logo

Double the Donation

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Double the Donation is SOC 2 Type II compliant.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Our Company: Double the Donation, a SOC 2 Type 2 compliant organization, is the leading provider of corporate employee matching gift tools. Through the use of our matching gift software, nonprofits, schools, and universities significantly boost their matching gift and volunteer grant revenue. Our Platform: Double the Donation is a matching gifts automation platform that automatically identifies match-eligible donors based on the information they provide during the donation process. Depending on their eligibility status, the platform triggers customizable follow-up emails outlining the relevant

Compliance & infrastructure

Hosting
Azure
Data handled
Employee personally identifiable informationCredit card informationPersonal health informationDonation data relevant for matching gift communications

Subprocessors

4
  • M
    Microsoft Azure · Cloud provider
  • G
    GitHub · Version control
  • V
    Vanta · Compliance
  • S
    SendGrid · Email sending

Compliance leadership

The person who leads Double the Donation's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Double the Donation's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Double the Donation SOC 2 compliant?
Double the Donation is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Double the Donation SOC 2 Type I or Type II?
Double the Donation is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Double the Donation's SOC 2 for a vendor risk assessment?
Yes. Double the Donation's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Double the Donation penetration tested?
Double the Donation hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Double the Donation secure?
Security isn't a single yes/no, but Double the Donation is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.

Answers published by Double the Donation

Reproduced from Double the Donation's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Where can I learn more about Double the Donation's password policies?
Internal user authentication policies for Double the Donation's staff are outlined in the "Access Control Policy" document, found under "Resources" in this Trust Center. Information about user authentication for the client-facing portal, not Double the Donation’s internal systems, can be found here. Specifically, reference password requirements here and multi-factor authentication functionality here.
How does Double the Donation handle data deletion?
Double the Donation clients can delete data from their accounts at any time, directly from the client portal. Double the Donation can also delete customer data in bulk upon request (typically unnecessary, given easy client access to deletion). Double the Donation relies on Azure for data destruction and can only perform logical deletion. Deleted customer data is rendered unreadable or disabled by Azure and the underlying storage areas on the Azure network that were used to store the content are wiped, prior to being reclaimed and overwritten, in accordance with Azure standard policies and deletion timelines. Azure procedures also include a secure decommissioning process conducted prior to disposal of storage media used to provide the Azure services. As part of that process, storage media is degaussed or erased and physically destroyed or disabled in accordance with industry standard practices.
Where are Double the Donation's servers located?
Double the Donation's database and platform are hosted on Microsoft Azure servers in the Virginia location. More information here.
What is Double the Donation's historical uptime?
Double the Donation's availability is consistently above 99.99%. Any customer data is 100% backed up to multiple online replicas with additional snapshots and other backups. Double the Donation relies on site24x7 to monitor uptime. Double the Donation also relies on Sentry notifications to broadcast all errors and warnings to senior developers via email and Slack. For the underlying database, Double the Donation logs all queries that take more than 200 milliseconds to execute and uses that data to routinely optimize. Double the Donation also uses Datadog to monitor uptime and alert team members to disruptions. For more information, view our SLA here.
Which data points need to be accessed by Double the Donation?
The sole purpose of data sharing with Double the Donation is to increase nonprofit organizations’ employer matching gift revenue and to provide actionable insights on donor behavior. The data points that are expected to be shared from client organizations into their accounts are: - Donor first name - Donor last name - Donor's email address - Transaction ID - Donor's phone number - Donor's employer - Campaign the donor gave to - Donation amount In almost all cases, Double the Donation collects the above data points by utilizing turnkey integrations with donation forms and CRMs. These integrations, configured by each individual client, automatically pass transaction level details into clients’ Double the Donation account once donations are made online or via continuous syncs from a CRM at predetermined intervals. Only identified fields from connected objects and modules will be passed into Double the Donation. Double the Donation does not have access to any additional data from connected systems.