Security Features of BenefactorCloud

Accreditations & Partners

Cyber Essentials
bonterra logo
MS
merkai
solar winds
Fidelit

Protecting Grantmaking Data: BenefactorCloud Security in Light of Recent Sector Breaches

Recent high-profile cybersecurity incidents across the non-profit sector have served as a sharp wake-up call for grantmaking bodies, trusts, and funding organisations. While a recent incident involved donor management software, the underlying vulnerabilities highlight a critical truth: any software platform holding sensitive sector data is a target for cyber criminals.

Unlike CRM systems that store constituent giving records, grant management platforms can handle an exceptionally sensitive array of applicant, organisational, and financial information. This includes detailed project proposals, confidential financial accounts, applicant personal demographic data, peer review assessments, and bank details for grant disbursements. A breach within a grantmaking environment can expose vulnerable applicants, compromise confidential funding strategies, and derail vital grant programmes.

As a specialised grant management platform available on procurement frameworks such as G-Cloud 15, BenefactorCloud was engineered with security best practice at its core, ensuring grantmakers can process applications and distribute millions of pounds (£) in funding with complete peace of mind.

Understanding Sector Vulnerabilities Highlighted by Recent Breaches

Several recurring security vulnerabilities common across cloud software platforms serving non-profits and funders can include:

  • Over-privileged user access: Weak permission structures allowing unauthorised lateral movement across application and financial databases.

  • Insufficient data isolation: Multi-tenant environments lacking rigorous logical partitioning between organisation accounts.

  • Unencrypted communication channels: Vulnerabilities during data transmission between third-party API integrations and core management modules.

  • Delayed threat detection: A lack of automated, real-time intrusion monitoring to identify unusual data exfiltration or malicious queries.

To address some of these systemic risks, BenefactorCloud employs technical and organisational measures tailored to the complex data lifecycle of grant administration.

BenefactorCloud’s Technical Security Features: Detailed Overview

Drawing directly from BenefactorCloud’s technical architecture and Security Overview, the platform delivers enterprise-grade protection across every operational domain:

1. UK Hosting, Network Isolation and Infrastructure Security

BenefactorCloud is hosted within the United Kingdom using Amazon Web Services (AWS) in the London availability zone (eu-west-2). The application operates inside a Virtual Private Cloud (VPC).The underlying data centre infrastructure complies with SOC 1, SOC 2, SOC 3, and Cloud Security Alliance controls.

2. Multi-Layered Encryption & Software Security for Bank Details

All stored application data, databases, and media files are encrypted at rest using AWS EBS AES-256 encryption managed via AWS Key Management Service (AWS KMS). Data in transit across web interfaces is protected using TLS 1.3 (HTTPS) with SHA-256 signed certificates.

Crucially, BenefactorCloud applies an additional layer of software encryption specifically to applicant and grantee bank details. These sensitive payment credentials can only be decrypted and accessed through the dedicated Finance Module within the software, minimising risk for both the account holder and the grantmaking organisation.

3. Granular Access Controls, MFA and Bias Controls

Grant management requires sharing confidential information across internal staff, external assessors, and panel members. BenefactorCloud enforces strict access management:

  • Mandatory Multi-Factor Authentication (MFA): Enforced across user accounts to prevent unauthorised entry via compromised credentials.

  • Granular User Permissions: Administrators can restrict assessors and panel members exclusively to assigned applications, preventing unauthorised viewing of applicant financial or personal data.

  • Bias Controls for Unbiased Assessment: Built-in bias controls allow grant managers to withhold or anonymise specific identifying applicant information during review stages, protecting applicant privacy and supporting fair, equitable grant distribution.

  • Single Sign-On (SSO): Integration via Microsoft Entra ID (formerly Azure AD) allows users to authenticate seamlessly using a Microsoft account linked to their organisation.

4. Application Security, AWS WAF & Threat Defense

To prevent malicious exploitation, BenefactorCloud restricts database procedures and parameterises code blocks to prevent SQL injection attacks, prohibiting attackers from manipulating database functions. Real-time web application monitoring, threat filtering, and DDoS protection are actively managed using AWS WAF (Web Application Firewall) and AWS Shield.

5. Independent CREST Security Testing & OWASP Assurance

To validate its security posture, BenefactorCloud undergoes regular external penetration testing conducted by CREST-approved security auditors. These independent assessments evaluate the application and supporting infrastructure against the OWASP Top 10 vulnerabilities (including injection, broken access control, server-side request forgery, and cryptographic failures), with test summary reports available on request.

6. Auditability, Secure Messaging & Disaster Recovery

BenefactorCloud maintains a clear, immutable audit trail recording decisions, scoring inputs, and workflow changes throughout the grant lifecycle. Secure messaging with applicants is retained directly within BenefactorCloud and grouped by topic, eliminating unencrypted email exchanges. Data resilience is ensured via AWS Point-in-Time Recovery (PITR), providing continuous database backups and rapid recovery.

7. UK GDPR and Regulatory Compliance

Fully compliant with the UK Data Protection Act 2018 and UK GDPR guidelines, BenefactorCloud includes built-in compliance tools to assist Data Protection Officers with Subject Access Requests (SARs), automated redaction, and configurable retention schedules for archived or declined grant applications.

Best Practices for Grantmakers to Safeguard Funding Operations

While selecting a secure grant management platform like BenefactorCloud provides a robust technical defence, grantmaking bodies should also maintain strong operational hygiene:

  1. Audit User Permissions Regularly: Review active user accounts at the end of each funding round and immediately revoke access for external assessors once evaluations are complete.

  2. Enforce Mandatory MFA for External Reviewers: Require external panel members to use multi-factor authentication when accessing confidential application packs.

  3. Safeguard Financial Export Tools: When using export tools that work with external accounting and finance systems, ensure file exports are encrypted and restricted to authorised finance personnel.

  4. Train Staff to Spot Phishing: Conduct regular awareness training for grant managers to recognise social engineering attempts aimed at hijacking grant disbursement bank details.

Conclusion: Safeguard Your Grantmaking with Enterprise Cloud Security

Recent cybersecurity events in the non-profit ecosystem highlight the absolute necessity of robust cloud security. For grantmaking organisations, protecting applicant trust, safeguarding financial assets, and ensuring uninterrupted funding delivery require software built specifically for secure governance.

BenefactorCloud delivers peace of mind by combining UK-based cloud isolation, specialized bank detail encryption, CREST-tested application security, and granular permission controls—allowing funders to focus on delivering positive social impact.