Encryption
We use encrypted connections for data in transit and select hosting and storage services that support appropriate encryption at rest.
Security
Add25 is designed to handle donor, declaration, donation and charity information responsibly. Our security approach combines technical safeguards, controlled access and clear operating practices.
Our approach
Security controls will continue to develop as Add25 moves from preview into operational service. We do not claim certifications that have not been independently awarded.
We use encrypted connections for data in transit and select hosting and storage services that support appropriate encryption at rest.
Administrative and production access is restricted to authorised people with a legitimate operational need.
We aim to collect and retain only the information required to provide Gift Aid and related account services.
Technology and service providers are selected with security, privacy and contractual responsibilities in mind.
Operational events are monitored where appropriate, with processes for investigating and responding to suspected incidents.
Changes are reviewed and tested before release, with vulnerabilities and dependencies addressed according to risk.
Partners and charities
We can discuss data flows, integration responsibilities, subprocessors, retention and access requirements during partnership or charity onboarding. Detailed technical information may be shared under appropriate confidentiality arrangements.
Request a security discussion →If you believe you have found a security issue involving Add25, contact hello@add25.co.uk. Please provide enough detail for us to investigate and avoid accessing, changing or sharing data that does not belong to you.
This page summarises Add25’s security approach. It is not a certification, warranty or substitute for the contractual security terms agreed for an operational service.