SOC2C

Is this your company? Buyers are checking Engaging Networks here. Claim engagingnetworks.net free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Engaging Networks logo

Engaging Networks

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Engaging Networks is SOC 2 Type II compliant. Engaging Networks also holds HIPAA, GDPR, and PCI DSS.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Engaging Networks helps nonprofits maximize their impact through a suite of world-class online fundraising and advocacy tools. Nonprofits of every size and cause—from human rights to disaster relief—use our platform to raise money, engage their communities, and advance their missions. Engaging Networks is a flexible, completely customizable and innovative software platform for nonprofits. The company designs its system processes and procedures to meet its objectives which are based on the service commitments it makes to user entities, the laws, and regulations that govern the provision of the

Compliance & infrastructure

Hosting
AWS

Documents

1

Subprocessors

9
  • A
    Amazon Web Services · Cloud provider
    United States; Canada
  • C
    Cloudflare · Cloud monitoring
    Location of Data Subject through Cloudflare's Anycast Network
  • e
    eSolution · IT
    Canada
  • E
    Egnyte · Document management
    United States
  • E
    Engaging Networks software support services · IDTA
    United Kingdom, European Union
  • E
    Engaging Networks USA · IDTA, DPA
    United States
  • P
    Postmastery · Professional services
    Netherlands, Canada, United States
  • R
    Rackspace · Cloud monitoring
    Global
  • V
    Very Good Security · Cloud provider
    United States

Compliance leadership

The person who leads Engaging Networks's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Engaging Networks's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Engaging Networks Has Achieved SOC2 Type 2 Compliance! 2026 Report Available!Apr 2026

We are excited to announce that Engaging Networks has maintained SOC 2 Type II compliance in accordance with American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations also known as SSAE 18. This designation serves as third-party industry validation that Engaging Networks provides enterprise-level security for customers’ data secured in the Engaging Networks System. The security audit was performed by ControlCase (controlcase.com).

Engaging Networks 2026 PCI DSS AOC UploadedFeb 2026

An Attestation of Compliance is completed by a Qualified Security Assessor (QSA) to declare that a business complies with the Payment Card Industry Data Security Standard (PCI DSS). Engaging Networks is proud to announce that it has implemented necessary security controls to protect cardholder data, as demonstrated by its annual recertification.

Engaging Networks HIPAA Compliance Externally Validated - Certificate of Compliance AvailableDec 2025

We are excited to announce that Engaging Networks has achieved HIPAA compliance in accordance with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) of 1996 – “Security rule” and “Breach Notification”. This designation serves as third-party industry validation that Engaging Networks provides enterprise-level security for customer’s data secured in the Engaging Networks System. The security audit was performed by ControlCase (https://www.controlcase.com/), a leading provider of services and solutions that help organizations address regulations and standards such as PCI DSS, ISO27001/2, GLBA, HIPAA, CoBIT, SOC 2, etc.

GDPR documents uploaded.Dec 2025

Consolidating Engaging Networks GDPR documents to the Trust Center from other Engaging Networks online resources.

Engaging Networks SOC 2 Bridge Letter & HIPAA BAA UploadedJul 2025

A SOC2 Bridge Letter has been uploaded to the Resources section under Compliance Reports. This letter acknowledges the continued adequacy of internal security controls for the Engaging Networks platform since the end of the previous audit observation window. Additionally, Engaging Networks has uploaded a standard HIPAA Business Associate Agreement (BAA) for use with healthcare covered entities who desire to use the Engaging Networks platform. This document is uploaded in the HIPAA section of Resources.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Engaging Networks SOC 2 compliant?
Engaging Networks is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Engaging Networks HIPAA compliant?
According to Engaging Networks's public trust center, Engaging Networks is HIPAA compliant. On SOC2C this listing is Listed.
Is Engaging Networks GDPR compliant?
According to Engaging Networks's public trust center, Engaging Networks is GDPR compliant. On SOC2C this listing is Listed.
Is Engaging Networks PCI DSS compliant?
According to Engaging Networks's public trust center, Engaging Networks is PCI DSS compliant. On SOC2C this listing is Listed.
Is Engaging Networks SOC 2 Type I or Type II?
Engaging Networks is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Engaging Networks

Reproduced from Engaging Networks's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you support encryption in transit and at rest?
Yes, all data entering and exiting the EN platform is encrypted from the endpoint to our Internet proxy/load balancer using SSL. From there all traffic passes through a web application firewall and is then re-encrypted using SSL until it hits our web servers. We use TLS 1.2 for data in transit and have deprecated several ciphers available in TLS 1.2. For data at rest, we use Amazon EBS encryption, which uses AES-256.
Is the platform GDPR compliant?
Some of our clients may need to comply with the General Data Protection Regulation promulgated under EU 2016/679 if they acquire Personal Data from residents of the European Union. In those cases, Engaging Networks is a processor in the provision of the Services set forth under our standard Agreement. Clients are solely responsible for ascertaining whether they must comply with GDPR. While Engaging Networks provides GDPR compliant services, Clients shall only be in compliance with the GDPR if they have executed a Data Processing Agreement (DPA).
Where is EU or UK data processed?
When the cross-border transfer of data does occur, the personal data may be accessed from the USA but remains on our servers in Canada – and Canada has an adequacy decision with the UK / EU which recognizes that they provide an equivalent level of protection for personal data as the EU / UK does. Our aim is to be as transparent as possible when it comes to data protection and our role as a data processor for your Engaging Networks accounts. With this in mind, we have developed the following: - Data Processing Agreement (DPA) - International Data Transfer Agreement (IDTA) between Engaging Networks and Engaging Networks USA - A signed 'Linked Agreement' between the two parties - Transfer Impact Assessment Refer to this link for more detailed information on Engaging Networks' Data Protection Agreements: https://knowledge.engagingnetworks.net/softwaresecurityandprivacy/detailed-information-on-engaging-networks-data-pro
How does Engaging Networks help protect clients from fraudulent activity on donation forms?
One of the most popular anti-fraud measures that our clients implement on their web pages is a reCAPTCHA challenge, which is easily applied to any form when building the page and can be restricted to only appear for high risk countries. Engaging Networks also automatically blocks IP addresses that submit multiple rejected transactions in a period of time. Engaging Networks uses Cloudflare as one of our Web Application firewalls (WAF). This provides a significant detection, and mitigation capability to all hosted Engaging Networks content. We use Cloudflare managed rulesets as well as our own custom rulesets to mitigate malicious activity. More information can be found: https://developers.cloudflare.com/waf/ We have also implemented Cloudflare Bot Management. This capability allows us to identify bad bots and challenge (or block) them from accessing any hosted content while not impacting legitimate user access to sites. More information on this can be found: https://www.cloudflare.com/application-services/products/bot-management/ Additional fraud prevent measures include: Email/SMS fraud notification alerts: If a donation page repeatedly generates rejected transactions, it may indicate that someone is trying to abuse the page. When such activity is suspected, the software will notify clients via email and/or SMS, and suggest steps to improve the situation. Allowed domains: Pages will load only on a client’s custom subdomain, reducing attacks from spammers who take advantage of sequential pages on default domains. Spam traps: Ability to add a hidden field that can prevent page submissions by spambots but will be invisible to human supporters.
What is the backup policy?
Engaging Networks will provide data backups sufficient to enable recovery of all clients’ data in response to a system-wide event that affects the entire software platform, but not to recover the data of an individual client that deletes or damages the data that they store in their Engaging Networks software account. Therefore Client is responsible for making their own backup copy (e.g. in a separate CRM database of record, such as Salesforce) of the constituent data and transaction data that Client stores in their Engaging Networks account.