NGO Analytics
Security
Grant Ops and Fiscal Sponsor OS keep separate logins on one application host. This page is the public description of how we handle customer data and where we are on SOC 2. The marketing site at ngoanalytics.com is outside the production system boundary.
SOC 2 preparation
NGO Analytics is preparing a SOC 2 Type II examination covering Security, Availability, and Confidentiality. We are not SOC 2 certified. E-file / MeF transmission is outside the current system boundary.
Grant Ops and Fiscal Sponsor OS run on the same host with separate sessions. Production data is hosted on Supabase and DigitalOcean. A Type II report will be available under NDA after a six-month observation period.
Safe language for an RFP or vendor questionnaire: quote the two sentences above. Do not write “SOC 2 certified” or “SOC 2 compliant” until a CPA report is in hand for a named period.
System boundary
- In scope: Grant Ops and Fiscal Sponsor OS — application, Postgres, Auth, and Storage.
- Out of scope: ngoanalytics.com; a customer’s Single Audit or 990; paper or portal filings the customer submits themselves.
- E-file / MeF: adapters are not connected. A queued or blocked transmit is not a filed return and is not in the first SOC 2 exam (Processing Integrity stays out).
SOC 2 attests NGO Analytics’ SaaS controls. A customer’s Single Audit attests their federal spend. Those are different reports.
Controls in the product
- Organization-scoped roles with row-level security on every tenant table.
- TOTP MFA required for admin, filer, and accountant seats before those users can work.
- Invites bind to the addressed email. A different sign-in is rejected.
- Join codes are rotatable shared secrets, not a second invite channel for CPAs.
- Audit log of sensitive actions (role change, invite accept, transmit, retention).
- Retention days purge eligible files, notifications, and aged audit events (audit kept at least 365 days).
- AI suggestions stay in a human review queue. Nothing writes a CRM row on its own.
- The global filing catalog is written only by the service role, not by workspace users.
Hosting and subprocessors
- Supabase — Auth, Postgres, Storage (TLS in transit; encryption at rest at the host).
- DigitalOcean App Platform — the Next.js application.
- Optional LLM providers only if a workspace enables them. They are not a second system of record.
Request a DPA, the current subprocessor list, or (when issued) the Type II report under NDA at [email protected].