Encrypted connections
Public pages and signed-in sessions are served over HTTPS, so data moving between a browser and Benevolate is encrypted in transit.
Membership rolls, donor records, religious school families, visitor tickets, and payments sit in Benevolate. This page states what we operate today, what is finished, and what is still in progress.
What a board can rely on
Benevolate is built for organizations that keep sensitive community records. The items below are operating practices. Formal certificates are listed only after they are issued.
Public pages and signed-in sessions are served over HTTPS, so data moving between a browser and Benevolate is encrypted in transit.
Staff see the areas their role allows. A front-desk user, a development director, and an executive do not share the same permissions. Authenticator-app multi-factor authentication is available for sign-in.
Passwords are stored as salted one-way hashes. We do not keep them in a form that can be read back.
Card payments are processed by Stripe, a PCI DSS Level 1 service provider. Benevolate does not store full card numbers. Sensitive payment references we retain are encrypted with AES-256-GCM.
Production runs with our cloud provider. We watch provider advisories and tell customers when a disruption may affect service.
Who this is for
Preparedness
We monitor the network and application health. Failed checks alert our operations team so we can respond while the issue is still contained.
Anyone can check current status at benevolate.com/health/status. If the application itself cannot render that page, a static notice is still served.
When we know a disruption is possible, we tell the organizations affected, with enough detail to plan around it.
Our cloud provider recently advised us of a potential disruption of about two hours. We notified customers about that window. Your staff should hear it from us, with enough time to plan High Holiday services, a campaign close, or a museum opening weekend.
Send the questionnaire. We will answer against this posture, including the items that are still pending, rather than stretch a claim.
Updated October 2026. This page describes current operating practices. It is not a warranty, a penetration-test certificate, or a SOC 2 report. No method of transmission or storage is absolutely secure. Privacy practices are described in the Privacy Policy.