Security & Data Protection

How we protect your organisation’s data

Last reviewed  September 2026 Questions  info@easygovernance.ie

EasyGovernance holds the records an organisation is trusted to protect — board papers, governance documents, donor details and financial history. This page sets out, in plain terms, how that data is kept safe, where it lives, and who can reach it.

If your board or a professional adviser needs a deeper technical review or a formal Data Processing Agreement, we're glad to provide one — details at the end.

Where your data lives

Your platform data — documents, board records, donor and financial information — is stored and processed entirely within the European Union, in Amazon Web Services' Ireland region. It does not leave the EU in the normal course of operation.

Encryption, in transit and at rest

Every connection to the platform is encrypted with TLS, so data in motion can't be read in transit. Data at rest is held on encrypted storage.

The most sensitive fields go further: PPS numbers are individually encrypted with AES-256 at the application layer and can be decrypted only by an authorised administrator of your organisation, never by ordinary users and never in bulk.

One organisation can never see another's data

EasyGovernance is multi-tenant — many organisations share the same platform — so this is the boundary that matters most. It's enforced by Row-Level Security in the database itself, on every table, not merely in the application. Your organisation's records are invisible to any other organisation at the deepest level, so even an application error cannot leak data across that line. This isolation is re-verified automatically on every release.

People see only what their role allows

Access is granted by role and capability: an owner or administrator, a board member, a treasurer, someone who handles income. Each person reaches only the areas their role permits, and the system is fail-closed — if a permission hasn't been explicitly granted, access is denied by default rather than allowed. Administrators manage their own team's access from within the platform.

Sign-in and account security

Accounts are protected by a managed authentication service. We never see or store your password in readable form. Team invitations use single-use links tied to a specific person, and password resets are self-service — so access can be granted and revoked cleanly as your team changes.

Payments never touch our servers

All card payments are handled by Stripe, a PCI-DSS Level 1 provider. Card numbers are entered directly into Stripe's secure systems and never pass through or rest on EasyGovernance. We record that a payment happened, not the card that made it.

A complete, tamper-evident audit trail

The platform keeps an append-only record of who did what, and when — across documents, board meetings, donor records and consent actions. Entries are added, never quietly edited or removed. This is what lets you produce evidence on demand for a regulator, auditor or the board, and show not just the current state but how you got there.

Backups and continuity

Your documents in the vault are backed up automatically every night to separate, encrypted storage in the EU, so they can be restored in the event of a failure. The database that runs the platform is additionally protected by our cloud provider's managed daily backups.

Security built into every release

Security isn't a one-off review. Automated checks run in our build pipeline and block insecure changes from ever shipping — verifying that data-isolation rules cover every table, that database functions can't be reached by anyone unauthorised, and that no view exposes data across organisations. A strict content-security policy limits what can run in the browser.

Your data is yours

The document vault belongs to your organisation. Your records remain yours, and you can export your data and reports at any time.

The services that process your data
ServiceWhat it doesWhere
Supabase / AWS Database, file storage and hosting — the core platform and your vault EU · Ireland
Stripe Card payment processing (PCI-DSS Level 1) EU / global
Resend Delivery of transactional email — invitations, reminders, notifications USA
Cloudflare R2 Encrypted off-site backup storage EU

A deeper review, whenever your board wants one

We're happy to walk your board or a professional adviser through any of the above in more detail, provide a Data Processing Agreement, or answer specific diligence questions.

Contact  info@easygovernance.ie  ·  Print this page