Secure by design

WealthAtlas is SOC 2 Type II and HIPAA compliant, with enterprise-grade security built into every layer of the platform.

Enterprise-grade security

The controls behind each of these are independently audited and monitored continuously.

Data encryption

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). That covers every profile, your uploads, and everything in between.

Single sign-on & SCIM

WealthAtlas integrates with SAML and OIDC providers including Okta, Azure AD, and Google. SCIM supports automated provisioning and deprovisioning.

Role-based access

Permissions are role-based and scoped to your team. Internally, access follows least privilege and is reviewed regularly.

Infrastructure security

WealthAtlas is hosted on AWS and Vercel in the United States. Production environments are isolated from development, and every change is peer-reviewed before it ships.

Continuous compliance

Security controls are monitored continuously against SOC 2 requirements — not checked once a year.

Monitoring & incident response

Production systems are logged and monitored around the clock, with alerting and an incident response plan for anything that needs attention.

Your data is not used to train models

We do not use your organization's data — contacts, uploads, or research — to train AI models, and our AI providers are contractually prohibited from doing so.

Never used for trainingNever soldNever shared

Two kinds of data. One standard of care.

Our data

Public records, cited to the source

Profiles are built from public sources — IRS nonprofit filings, campaign finance records, SEC filings, property records, and news. Every fact links back to where it came from.

  • Built on public records
  • Cited on every profile
Your data

Imported by you, visible only to you

The data your organization imports into WealthAtlas — contacts, files, research notes — is confidential customer data. It is encrypted, visible only to your team, and never mixed into anyone else's results.

  • Never sold or shared
  • Never used to train AI models

Common questions

Is WealthAtlas SOC 2 compliant?
Yes. WealthAtlas undergoes regular SOC 2 Type II audits by an independent firm. To request the report, email team@donoratlas.com.
Is WealthAtlas HIPAA compliant?
Yes. WealthAtlas is HIPAA compliant and operates as a Business Associate, and we are ready to sign a BAA with your organization.
Where is my data stored?
Customer data is stored in AWS data centers in the United States. It is encrypted at rest and does not leave the US.
Is my data used to train AI models?
No. We do not use your data to train AI models, and our AI providers are contractually prohibited from training on it. Your data is never sold or shared.
Who can see my data?
Only your team. Data you import into WealthAtlas is scoped to your organization and is never visible to other customers. Internal access is limited to the employees who need it to support you.
How do I report a security issue?
Email team@donoratlas.com with a description of the issue. We review every report, and we appreciate responsible disclosure.
Can you complete our security questionnaire or sign a DPA?
Yes. Email us for questionnaires, DPAs, policies, or compliance reports and we'll turn them around quickly.

Questions about security?

Compliance reports, policies, questionnaires — email us and we'll get you what you need.