Security & Compliance
DonorCARE is the system of record for Malaysian NPO donations, tax receipts, and LHDN e-invoice history. Security and sovereignty are foundational — not features.
Multi-tenant data isolation
Every organization's donors, donations, campaigns, and receipts are strictly scoped by
organization_id. All queries enforce tenant filters at the service layer; row-level security and permission checks gate both admin and public API access.Authentication & access control
Cookie-based sessions for admin/frontend (Better-Auth), API keys for service accounts. Role-based permissions:
org_owner, org_admin, donor, superadmin. Superadmin actions fully audited. OAuth + email/password supported.Data at rest & in transit
PostgreSQL on Neon with encryption at rest. All API traffic over TLS 1.3. Payment credentials (CHIP keys, SendGrid keys, LHDN tokens) encrypted with per-field key derivation; never logged in plaintext.
LHDN & Malaysian sovereignty
Compliance with LHDN MyInvois requirements for e-invoice submission, cancellation, and document lifecycle. Section 44(6) of the Income Tax Act 1967 receipt rules enforced at the receipt engine. TIN validation against LHDN records. Data resides in Malaysian-available AWS ap-southeast-1 region.
Audit trail
Every mutating action (donation create, receipt issue, MyInvois submission, member change, Copilot action) writes an immutable audit log with user, IP, timestamp, old/new values, and entity reference. Superadmin-visible, org-scoped-visible to admins. Retained for 7 years.
AI Copilot guardrails
Copilot reads are scoped to the requesting organization. Write actions (Ring 3) require explicit human approval before execution and are logged in the audit trail. No cross-org data is surfaced in conversations. No prompts or data are used for model training by our providers.
Backups & recovery
Point-in-time recovery on Neon (7-day window). Nightly logical backups. Disaster recovery RTO 4 hours, RPO 1 hour.
Vulnerability disclosure
Report security issues to security@donorcare.my. We acknowledge within 24 hours and patch critical issues within 72 hours.

