Security and trust

adiNGO is being operated toward SOC 2 readiness with privacy and security controls designed for sensitive NGO services. No independent SOC 2 report has been issued yet.

Report a security concern

Access control

Least privilege, staff MFA, programme scoping, time-bound privileged access, and scheduled access reviews.

Protected information

Private files, restricted classifications, explicit API fields, access evidence, encryption, and safe notifications.

Monitoring and response

Central monitoring, incident triage, breach decision records, recovery procedures, and response exercises.

Availability and recovery

Monitored backups, off-site copies, recovery targets, restore testing, and documented disaster-recovery exercises.

Secure delivery

Reviewed changes, automated tests, vulnerability management, dependency scanning, and tracked exceptions.

For safety, this public page does not expose infrastructure diagrams, control-test evidence, vulnerabilities, incident details, or configuration that could weaken the service.