Rethinking Generosity

Security & Compliance

Bounded Retention. AI4Love holds one working Airtable base per organization in AI4Love's account as a service provider. The base is isolated per organization. It exists only while service is active plus a 90-day exit window, then it is deleted. Full export is available on request. The client organization remains the institution responsible for the personal information under FIPPA. An organization-held mirror (Owned Copy) is designed but not running in production and is described only as planned. Immediate deletion is available on request.

Full technical details: The AI4Love Trust Center is the canonical reference for how AI4Love handles your data, including system architecture, data flow diagrams, failure modes, and incident response procedures.

Bounded Retention across the stack

Source systems stay the systems of record. What AI4Love holds is bounded, isolated, exportable, and deleted when you leave:

  • Source systems (Blackbaud, Mailchimp, Environics) — Read-only integrations. AI4Love never writes back to your source platforms.
  • Working base (Airtable, AI4Love's account, isolated per organization) — AI4Love writes only AI-generated insight records, enrichment fields, and campaign-workflow metadata through scoped application code. Deleted after the 90-day exit window.
  • LLM providers (Anthropic, OpenAI) — API-tier usage only. Neither provider trains on your data. Inputs are retained up to 30 days for trust and safety, then deleted.
  • Credential stores (Nango, Doppler) — Hold access tokens, not supporter data. Revocation destroys tokens immediately.

Encryption

All data is encrypted at every layer:

  • In transit — TLS 1.2+ on all API calls, webhooks, OAuth flows, and MCP queries. No plaintext connections accepted.
  • At rest — AES-256 across Airtable, Nango, Doppler, and Vercel.

Data Classification

AI4Love processes supporter engagement data: donation history, volunteer activity, event participation, and communication records.

AI4Love does not require and does not process:

  • Protected health information (PHI)
  • Financial account numbers, credit card data, or banking details
  • Government-issued identifiers (SIN, SSN, driver's licence)
  • Biometric data

If your Airtable base contains fields outside the engagement data scope, AI4Love applies allow-list field filtering before passing data to any sub-processor.

Allow-List Field Filtering

AI4Love applies deterministic, code-defined filtering at two boundaries:

  • Agent prompts — Each agent's prompt template declares exactly which fields it needs. Only those fields are included. Adding a new field to Airtable does not automatically expose it to the LLM.
  • MCP responses — Before passing data to an AI assistant, the MCP server filters responses to include only approved engagement fields. All other fields are blocked by default.

This is rule-based filtering, not an AI judgment call.

Per-Organization Isolation

Every organization gets its own dedicated Airtable base, its own credentials, and its own access keys. There is no shared tenancy at the data layer. A user authenticated for one organization cannot access another organization's data under any circumstances.

Credential Management & Revocation

  • OAuth tokens — Stored in Nango (SOC 2 Type II). AI4Love servers never persist tokens to disk.
  • API keys — Stored in Doppler (SOC 2 Type II). Never committed to code or logs.
  • Revocation — Staff can disconnect any integration from the dashboard. MCP access keys are validated per-request — revoking a key takes effect on the next request.

Infrastructure Partners

All sub-processors maintain SOC 2 Type II certification:

ProviderRole
AirtableData storage (supporter records, insights)
VercelApplication hosting and compute
NangoOAuth credential management
DopplerSecrets management
AnthropicLLM provider (Claude API)
OpenAILLM provider (ChatGPT API)

AI4Love does not currently hold its own SOC 2 Type II certification. All data storage and processing is delegated to SOC 2 Type II certified providers.

Compliance Frameworks

AI4Love's architecture is designed to support compliance with:

  • PIPEDA — Personal Information Protection and Electronic Documents Act
  • Provincial privacy legislation (e.g., BC PIPA, Ontario PHIPA): subject to your privacy assessment of US-hosted processing.
  • CRA requirements for charitable organizations
  • CASL — AI4Love does not send communications, but insight data can inform CASL-compliant outreach by your team

Incident Response

PhaseTimeline
DetectionContinuous automated monitoring
ContainmentWithin 4 hours
NotificationWithin 72 hours of confirmed breach
InvestigationWithin 7 days
RemediationWithin 14 days

Data Residency

All infrastructure is US-hosted. Canadian data residency is not currently available.

Available on Request

  • Data Processing Agreement (DPA) — customizable per organization
  • Sub-Processor List with roles, data access scope, and certifications
  • SOC 2 Type II reports from infrastructure providers (under NDA)
  • Penetration testing is on our roadmap; results will be shared with partner organizations on completion
  • Pre-filled vendor security questionnaire responses (SIG Lite, CAIQ, HECVAT)

For detailed security information, visit the AI4Love Trust Center or contact privacy@ai4love.ca.

Ready to Get Started?

Implementation begins with a conversation about your data, your team, and what you're missing today.

Get in Touch