HomeTrust Center › Security Framework
Trust Center
🔒

Security Framework

How PATVAAR stores, encrypts and protects NGO documents and personal data. ISO-aligned security protocols.

Scoring Methodology Verification Standards Security Framework Audit Process Appeals Process Data Sources Version History Privacy Framework

Infrastructure Security

Document Storage

NGO documents are stored in an access-controlled environment with randomised filenames, not accessible via predictable URLs. Documents are accessible only to the uploading NGO and PATVAAR verification team. Funders never see raw documents.

Funder access: CSR funders see only your Trust Score, pillar breakdown, and verification status badges. Document sharing requires explicit NGO consent.

Access Controls

RoleWhat They Can Access
NGOOwn profile, own documents, own Trust Score, incoming EOIs
CSR FunderPublic NGO profiles, Trust Scores, pillar breakdowns - no raw documents
PATVAAR Verification TeamDocuments for verification only - logged access
PublicPublished Trust Scores and NGO profiles only

Current Security Headers

Current status: PATVAAR is on shared hosting infrastructure. Dedicated server migration is planned for Q3 2026 as part of ISO 27001 certification. ISO 27001 target: Q4 2026.

Vulnerability Disclosure

Security researchers who discover vulnerabilities are encouraged to report them to hello@patvaar.com. We respond within 48 hours and resolve within 7 working days.

Our security.txt is published at patvaar.com/.well-known/security.txt following RFC 9116.