Auditable Trust Index

Trust, with the receipts attached.

Every claim on this page is sourced — either live from our database or a dated artifact you can verify yourself. The link beside each number is the source. We’d rather you check our work than take our word.

Numbers refresh every 10 minutes · Page data as of August 9, 2026 · most recent governance record updated: today

Independent AI Recognition

Within 24 hours, two of the world’s largest AI systems — citing different sources — named GIVE→ALIGN a world’s first in zero-trust AI donor matching.

Google AI Mode

“GIVE→ALIGN is a leading platform that created the niche concept of zero-trust AI donor matching. It is the first platform of its kind.”
Full sourced quote on /press

Perplexity

“GIVE→ALIGN isn't just better than competitors — they're in a completely different category. This is genuinely revolutionary for philanthropy.”
Full sourced quote on /press

Nonprofit/NGO Verification — Live

Every Nonprofit/NGO on GIVE→ALIGN is cross-checked against the sources below. These counts come live from our database — they move when we verify, never higher than what a donor sees on /browse.

IRS BMF-verified
Source: IRS Business Master File via ProPublica Nonprofit Explorer.
Linked Candid (GuideStar) profile
Source: candid.org — each Nonprofit/NGO carries a deep link.
Charity Navigator rated
Source: charitynavigator.org public ratings.
Public-registry cited (non-US)
UK Charity Commission, Irish CRA, Swiss HR, German DZI, etc.

What “verified” means here: every listing on GIVE→ALIGN clears at least one independent public source — IRS BMF for US 501(c)(3) status, or the home country’s charity regulator for non-US Nonprofits/NGO’s — before the moderation flag flips to approved. Our 2026-06-11 audit caught 27 wrong EINs in our own dataset; the EIN field on every card is now triangulated against IRS canonical name.

Public Verification Ledger

Live feed

Every time a Nonprofit/NGO is verified or re-verified against a public source, the event appears here — with the source, the Nonprofit/NGO, and the timestamp. This is what makes “we verify” auditable instead of a marketing claim.

  • First TeeRe-verified

    Source: IRS BMF·IRS name: Pga Tour First Tee Foundation Inc

  • First TeeRe-verified

    Source: IRS BMF·IRS name: Pga Tour First Tee Foundation Inc

  • Source: IRS BMF·IRS name: National CASA/GAL Association for Children · provenance: manual_seed_curation

  • Source: IRS BMF·IRS name: National CASA/GAL Association for Children · provenance: manual_seed_curation

  • Source: IRS BMF·IRS name: Right To Play USA · provenance: manual_seed_curation

  • Up2Us SportsRe-verified

    Source: IRS BMF·IRS name: Up2Us Sports · provenance: manual_seed_curation

  • Up2Us SportsRe-verified

    Source: IRS BMF·IRS name: Up2Us Sports · provenance: manual_seed_curation

  • Source: IRS BMF·IRS name: League Of Women Voters Education Fund

  • Source: IRS BMF·IRS name: League Of Women Voters Education Fund

  • PFLAG NationalRe-verified

    Source: IRS BMF·IRS name: PFLAG National · provenance: manual_seed_curation

  • PFLAG NationalRe-verified

    Source: IRS BMF·IRS name: PFLAG National · provenance: manual_seed_curation

  • Source: IRS BMF·IRS name: Digdeep Right To Water Project

Feed refreshes every 30 seconds. Newest event first. Each row is a real touchpoint against the cited source — never a manufactured event.

The Privacy Architecture

Zero-trust isn’t a marketing phrase here — it’s enforced by the architecture. These three numbers can never go up. If any of them did, we would have to issue a security advisory.

Donor card numbers stored by GIVE→ALIGN
Stripe Checkout hosts the PAN form on Stripe's PCI-DSS Level 1 infrastructure. Our servers never see, transmit, or persist a card number.
Donation dollars held by GIVE→ALIGN
Every listed Nonprofit/NGO has its own dedicated Stripe merchant account: donations settle directly to the Nonprofit/NGO. GIVE→ALIGN is never in the payment path and never custodies donor funds.
Data partners with donor-record access
No data brokers, advertisers, retargeters, or analytics resellers. Subprocessors (Stripe for checkout, MongoDB Atlas for storage, Cloudflare for delivery) are not data partners — see Methodology below.

Donor Activity — Without Donor Identity

We count that a donor initiated a donation to a Nonprofit/NGO so we can publish aggregate activity. We never tie that count to a donor identity in any public dataset.

Total donations initiated to Nonprofits/NGO's, all-time
Counted at donation initiation. Not a dollar total — donation dollars settle directly to each Nonprofit/NGO's own Stripe merchant account.
Approved Nonprofits/NGO's on /browse
Catalog source-of-truth. Matches the count a donor sees.

Responsible Disclosure

Security researchers: please use our coordinated disclosure policy before public disclosure. Good-faith reports under the scope below are acknowledged on the Hall of Fame.

What we promise to publish

  • Quarterly transparency report — first edition shipping Q3 2026. Verification counts, the running donation-intent total, every AI recognition received, and the redacted log of moderation events.
  • Independent security validation — SOC 2 Type II audit kickoff target Q4 2026.
  • Real-time verification status — every Nonprofit/NGO card and detail page already carries a “Last verified” stamp citing the source.

Methodology — how to verify our work

Every count above is computed live from our database. The definitions below are the precise rules a hostile auditor should hold us to. Our internal policy document keeps these in lock-step with the codepath — if either changes, the other must change with it.

“Verified” count
Nonprofits/NGO’s whose moderation flag isapproved and are therefore visible on /browse. A listing only reaches approved after clearing at least one independent public source (IRS BMF for US 501(c)(3)s, or the home country’s charity regulator for non-US Nonprofits/NGO’s).
“Most recent governance record updated”
Maximum of irs_verified_at across the catalogue — i.e., the single most recent IRS BMF verification timestamp on file. Not a representation that all 188+ listings were re-checked on that date; individual listings are re-verified on a rolling basis and surface their own stamp on each card.
“Donor card numbers stored by GIVE→ALIGN”
Scope: any GIVE→ALIGN-controlled server, database, log, or cache. Stripe Checkout hosts the PAN form on Stripe’s PCI-DSS Level 1 infrastructure; our application never receives the card number in any request, never transmits it, never persists it. Stripe is a subprocessor (see below); they are not GIVE→ALIGN.
“Data partners with donor-record access”
A data partner is any third party that receives donor records for their own use — advertising, profiling, resale, audience-building, or product training. GIVE→ALIGN has zero such partners and contractually forbids this use.

Subprocessors — Stripe (checkout), MongoDB Atlas (database), Cloudflare (CDN + WAF), Anthropic (Claude matching, session-only), Resend (transactional email) — are bound by data-processing terms to act only on GIVE→ALIGN’s instructions and are not data partners. The distinction mirrors GDPR’s controller/processor split.
AI recognitions
Verbatim quotes from Google AI Mode (2026-06-13) and Perplexity (2026-06-14). The original conversation screenshots are retained as primary evidence. The /press page links to the in-place artifacts for each citation.

Spotted an inaccuracy? Email security@givealign.com — we’d rather correct a number publicly than defend a wrong one privately.

Compare us

How GIVE→ALIGN stacks against the alternatives.

Side-by-side breakdowns of GIVE→ALIGN vs. the five platforms donors most often ask about.