Skip to content

Your security review starts here.Not on a sales call.

Ignite holds constituent records, gift histories, and payment activity for mission-driven organizations. This page is the public layer of that responsibility: how data is protected, how AI is governed, what is certified today, and how to request the documents that go deeper. All of it readable without a form.

30 minutes, live in Ignite, on a workflow you choose. No slide deck.

The governance model

Controls your team can see and configure.

Ignite ships AI teammates in every subscription, governed by stated permissions, configurable write gates, and a visible action history.

01

Agents prepare the work

Research, recommendations, and outbound drafts arrive for staff review. Nothing sends until you approve it.

02

Read-only by default

Agents start with read access. Write capability is granted per agent and per action, never assumed.

03

Approval gates you configure

Writes use the gates your team configures, and you can see what will change before approving one.

04

A full audit trail

Every agent action lands in an audit trail: what was proposed, who approved it, and what changed.

AI and your data

Intelligence without leakage.

The value of agents comes from reading your full record. That only works if the reading is protected, and if you can see exactly who does the processing. How the agents use that record is on the Ignite Intelligence page.

The stack is named, not vague

Ignite runs AI through Microsoft Foundry on Azure-hosted endpoints, with Anthropic Claude models hosted on Azure. AI processing stays in the U.S. Data Zone.

Your data is not training material

Your donor data is yours. Prompts and outputs are not used to train foundation models by default, and we will walk your reviewer through the data flow.

Answers carry their sources

Agent outputs cite the records they drew from, so trust is checkable instead of assumed.

The fundamentals

Security built into the platform.

Multi-tenant data isolation

Your data lives in its own tenant, separated from every other organization on the platform.

Encryption everywhere

Data is encrypted in transit, and encrypted at rest with AES-256.

Established payment rails

Gifts process natively through Stripe and PayPal, with ACH via PayPal Payflow.

Consent management, enforced

CASL, CAN-SPAM, and TCPA enforcement is built into the platform, and constituent communication preferences are honored on every send. Deceased records are refused at the send gate itself, including transactional email.

Role-based access

Access follows roles across CRM, Finance, and Marketing, so people see what their job requires.

A hardened data model

Deceased and anonymous handling, audit tracking, auto-numbering, and profile deactivation are built into the record itself.

Safe on an ordinary Tuesday.

Most data damage is not a breach. It is a bad import, a wrong merge, a bulk edit nobody reviewed. The platform is built for those days too.

Imports validate before they write

Data import maps and validates every record before anything touches your database, and a batch can be rolled back if something looks wrong afterward.

Merges you can take back

Duplicate-record merges are logged with a full audit history and can be reversed for 30 days.

Configured review before writes

Approval gates can hold agent writes for review before they touch the record.

Compliance status

Where certification stands.

A security review dies the day it finds a claim that was rounded up. So this section states plainly what we hold and how to verify it.

SOC 2 Type II

SOC 2 Type II is more than a certification we hold. It is an independent audit of the way the platform already operates: every control above is real today, and your reviewer can verify any of them in an evaluation.

StratusLIVE maintains a current SOC 2 Type II report, refreshed at least annually. Request it below and it is shared under NDA where one is needed, alongside any other security documents your review requires.

Going deeper

Need more than the public layer?

Some evidence is sensitive enough to control. Here is how the deeper layer works, so a request never turns into a fetch quest.

Writing your board’s AI policy? Start with theNonprofit AI Policy Template. The contractual layer, including the data processing addendum, is on thelegal page.

Everything above is public.

No form, no email, no cookie wall. Every section has its own link, so you can forward the exact answer a stakeholder needs.

Sensitive artifacts are controlled.

Detailed security responses and legal documents are shared in an active evaluation, some under NDA. We tell you which before you commit to anything.

Requests go to owners.

Email info@stratuslive.com with the subject "Security review", or raise it in your working session. Either way it reaches the people who own the answer.

Questions

Asked by every good IT reviewer.

Straight answers to the questions that come up in every security review. For anything deeper, bring your reviewer to the call.

Running the platform after the review is its own page: the IT & Operations page covers zero custom code, role-based access, and agent permissions day to day.

Which AI vendors see our donor data?

Ignite runs AI through Microsoft Foundry on Azure-hosted endpoints, with Anthropic Claude models hosted on Azure. AI processing stays in the U.S. Data Zone. Ask us to walk your reviewer through the full data flow.

Is our donor data used to train AI models?

Prompts and outputs are not used to train foundation models by default. Your donor data is yours, and your reviewer can trace the data flow with us before you commit.

Can AI agents change our data without us knowing?

Every action is recorded in an audit trail. Agents are read-only by default, and writes use the approval gates your team configures.

Who can see our data?

Your data is isolated in its own tenant, separated from every other organization on the platform, and encrypted in transit and at rest.

What happens if a data import goes wrong?

Imports are mapped and validated before anything writes to your database. If a batch still lands wrong, it can be rolled back, and duplicate merges can be reversed for 30 days.

How are payments handled?

Gift processing runs natively through Stripe and PayPal, with ACH via PayPal Payflow: established processors that specialize in payment security.

How does Ignite handle communication compliance?

Consent management with CASL, CAN-SPAM, and TCPA enforcement is part of the platform. Channel preferences, restriction statuses, and suppressions live on the constituent record and are honored on every send, and deceased records are refused at the send gate itself.

Can we control what our staff can see and do?

Yes. Access is role-based across CRM, Finance, and Marketing, and agent subscriptions and permission levels are managed through the Intelligence Hub.

Does StratusLIVE have a SOC 2 Type II report?

Yes. StratusLIVE maintains a current SOC 2 Type II report, refreshed at least annually. Prospects and clients can request it through the security documents request on this page, and it is shared under NDA where one is needed.

Do you answer security questionnaires?

Yes. In an active evaluation, your questionnaire goes to the team that owns each control, and sensitive artifacts are shared under NDA where one is needed. Email info@stratuslive.com or bring it to your working session.

Bring your toughest reviewer.

See one live workflow in 30 minutes, with real data and no slide deck.