Vendor security reviews · Nonprofit
Vendor Security Review & Questionnaire Support for Charities & Foundations
A vendor security review examines the platforms and agencies you are about to trust with your donor file, before the contract is signed rather than after the breach notice. Since Blackbaud proved that a fundraising vendor's failure lands on each charity that used it, boards increasingly want CRM selections, receipting platforms and mail houses vetted properly. We read the vendor's evidence, ask the questions your team would not know to ask, and translate the answers into a signable decision.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor relationships that carry your donor file
A typical charity's most sensitive data spends most of its life inside other companies' systems. Each handoff below deserves scrutiny proportional to what flows through it.
The donor CRM itself
Whether you are choosing between Keela, a Raiser's Edge-class platform or a Salesforce nonprofit build, the CRM holds constituent records, giving histories and often payment tokens, making it the single highest-stakes review you will ever run.
Donation processing and receipting services
Platforms like CanadaHelps sit between the donor's card and your ledger, issuing official receipts on your behalf. Their controls, subprocessors and data residency belong in your file, not just their marketing pages.
Direct-mail and telemarketing agencies
Campaign agencies receive extracts of your list as flat files, the least controlled format data can take. The review probes how extracts travel, who touches them, and when they are destroyed.
Wealth-screening and research tools
Services enriching your records with capacity estimates hold profiles that would mortify donors if leaked, so their retention and sharing practices need explicit answers.
Volunteer, grants and case-management platforms
Better Impact-style volunteer systems, SmartSimple-class grant portals and program case tools each hold a different community's information under different contracts, all reviewable with the same discipline.
Regulatory map
Legal reasons charities must vet vendors first
Outsourcing the work never outsources the accountability, and two regimes in particular make pre-contract diligence an explicit obligation rather than good practice.
Law 25 demands assessment before data leaves Quebec
Communicating personal information outside the province requires a privacy assessment concluding the data will receive adequate protection, which for a US-hosted CRM means doing the analysis before signing, not after migration.
Alberta PIPA flags foreign service providers
Organizations subject to the Act must notify individuals when using service providers outside Canada to handle their information, a duty that starts with knowing where each vendor actually hosts and processes.
Accountability follows the file under privacy statutes
Where BC PIPA or PIPEDA applies to an activity, your organization remains answerable for information in a contractor's hands, so contracts need safeguard, breach-notice and return-or-destroy terms with teeth.
CRA residency shapes hosting choices
Books and records, including receipt duplicates, must be kept at your Canadian address, which makes a platform's data residency and export capabilities a compliance question, not merely an IT preference.
Funder clauses flow down to your vendors
When a contribution agreement binds you to confidentiality and security standards, any vendor touching program data inherits those expectations, and the review confirms they can honour them.
What goes wrong
Vendor failures the review is designed to catch early
The sector's defining breach was a vendor breach, and its lessons form the checklist we run every prospective supplier through.
Weaknesses left unfixed behind reassuring branding
The US$49.5 million multistate settlement against Blackbaud faulted unaddressed flaws and misleading breach communications, proof that a household sector name is not itself evidence of sound practice.
Backups that outlive their purpose
The stolen Blackbaud data sat in backup files, exposing donors including bank details acknowledged months later. Reviews ask pointed questions about backup encryption, retention and destruction.
Breach terms that leave you uninformed
Charities learned of their 2020 exposure on the vendor's schedule, then owned the notification duty themselves. We negotiate notice windows, cooperation duties and cost allocation into the agreement.
Subprocessors you never heard of
Your file may flow onward to hosting, analytics and support contractors on other continents. The review surfaces the chain so consent language and assessments reflect reality.
Loose handling at campaign agencies
A list extract emailed unencrypted to a mail house, retained on a production server after the campaign, is a breach waiting for a timestamp. Agency reviews focus on transfer, storage and certified destruction.
Our vendor security reviews for charities & foundations
What our review covers before you sign
The service applies structured security assessment to the vendor's evidence and the contract in front of you, sized to the sensitivity of what the vendor will hold.

Evidence collection and reading
We obtain and interpret SOC 2 reports, ISO certificates, security whitepapers and questionnaire responses, separating substance from sales material.
Risk-tiered questionnaires
A CRM migration gets deep scrutiny; a newsletter tool gets a proportionate short form. Tiering keeps diligence rigorous where it matters and fast where it does not.
Data-flow and residency mapping
Where your donor, beneficiary or grantee data will live, transit and back up, mapped against CRA, Law 25 and Alberta notice duties.
Contract clause review
Safeguards, breach notification timelines, audit rights, subprocessor controls, and exit terms including data return and destruction, marked up for negotiation.
A decision memo for leadership
Findings, residual risks and recommended conditions in two pages the ED and board committee can act on, with the technical detail annexed.
How the engagement runs
Running a vendor review on a charity timeline
Most reviews complete within a procurement cycle, and urgency around a renewal or migration date is a scoping input, not a surprise.
Step 1
Define the data and the stakes
We start from what the vendor will hold, constituent records, payment data, case notes, and set the review tier accordingly.
Step 2
Engage the vendor for evidence
We send the questionnaire, request reports under NDA where needed, and handle the follow-up so your staff are not chasing security documents.
Step 3
Analyze and verify claims
Responses are checked against the actual reports and configuration facts, with gaps pursued rather than papered over.
Step 4
Report, negotiate, decide
You receive the memo and marked-up terms; we support the negotiation call if the vendor pushes back on conditions.
What it costs
What determines vendor review pricing
The main variables are the number of vendors in scope, the sensitivity tier of each, whether Quebec assessment obligations apply, and how cooperative the vendor's evidence trail proves to be. A single CRM review with contract markup is a well-bounded piece of work; standing up a review process across your full supplier list is a program we can phase.
Ongoing vendor oversight is also built into our Virtual Privacy Office retainer, which suits charities that expect several selections and renewals per year. We quote fixed fees per review tier after a short intake call.
Charities & Foundations: Vendor security reviews questions, answered
Five things above all: where our data and its backups live and for how long; what independent assurance exists, a current SOC 2 Type II or ISO 27001 certificate, not a marketing badge; how quickly and completely they commit to notifying us of an incident, in contract language; which subprocessors touch our file; and what happens at exit, including certified deletion of backups. The 2020 incident turned each of those from theoretical to proven failure modes, so a vendor unwilling to answer plainly is answering anyway.
If your organization is caught by Quebec's enterprise test and Quebec donors' information will cross the border, you must complete a privacy assessment before communicating data outside the province, concluding it will receive protection adequate under Quebec's principles. That means examining the vendor's safeguards, contract terms and legal environment, then documenting the analysis and any mitigating clauses. We build the assessment into the review so procurement and compliance finish together rather than in sequence.
Focus on the life of the extract. How is the file transferred, encrypted channel or email attachment; who at the agency can open it; is it passed onward to print or lettershop partners; when is every copy destroyed and how is destruction evidenced? Add contract terms restricting use to the specific campaign, prohibiting retention, and requiring breach notice. Agencies handle many charities' lists, and the good ones can answer these questions in a day.
Ask for the current SOC 2 Type II report under NDA, not the summary letter, and read three sections: the auditor's opinion, the exceptions noted, and the complementary user-entity controls, the duties the report assumes you perform, like enforcing MFA and managing your own user access. A Type I or a pending audit is a yellow flag proportional to data sensitivity. If reading audit reports is not a skill your team wants, that interpretation is precisely what this service supplies.
Set the cycle by tier: platforms holding your constituent database or beneficiary records deserve an annual evidence refresh, a check of the latest assurance report and any subprocessor changes; lower-risk tools can run on renewal dates. Re-review immediately on triggers such as an acquisition of the vendor, a disclosed incident anywhere in their client base, a hosting change, or a new integration that widens what they hold about your community.
More for charities & foundations
Other services for this niche
About this service
Answers & guides
- What is SOC 2, and does my business need it?
- What is the difference between SOC 2 Type I and Type II?
- Do you need a TRA before moving sensitive data to a new cloud provider?
- Building a Third-Party Vendor Risk Assessment Program That Scales
- Before You Move Sensitive Data to a New Cloud: The Case for a TRA
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.