Security & privacy

How we protect your data — our security posture

Every measure we take to protect volunteers and organizations: FCRA compliance, 2FA, biometric-gated API access, encryption, auditing — plus the downloadable Security Posture PDF for your board.

The data VolunteerBadge handles — background-check reports, identity documents, and volunteers' personal information — is among the most sensitive a nonprofit will ever entrust to a vendor. We take both data privacy and security seriously so that volunteers and nonprofit leaders are fully protected. This page summarizes every measure in effect; the same content, in a board-ready document, is available below.

📄 Security Posture & Data Protection Overview (PDF)

The full 10-page document — ready to forward to your board, IT team, or security reviewer.

Download the PDF →

Regulatory & FCRA compliance

  • FCRA-regulated screening: ScreenForge Labs, LLC operates VolunteerBadge as a consumer reporting agency regulated under the federal Fair Credit Reporting Act. Compliance is enforced by the workflow itself, not left to memory.
  • Consent first, always: no check runs without the volunteer's standalone FCRA disclosure and signed authorization, and organizations certify their permissible purpose.
  • Human review of every potential record: reports with possible records are never released automatically — a trained reviewer confirms the record truly belongs to the applicant first.
  • Built-in adverse action: pre-adverse notice with the report and CFPB “Summary of Your Rights,” a 5+ business-day waiting period, then the final notice — every step logged in an exportable audit trail. Volunteers can dispute report accuracy, triggering reinvestigation.
  • Non-conviction protections: clear reports exclude records older than 7 years, arrests without conviction, warrants, and dismissed cases.

Sign-in & account security

  • Two-factor authentication: TOTP codes from any authenticator app, enforced server-side on every page and API route — a stolen password alone opens nothing. Owners can require 2FA for their whole team.
  • Mandatory staff 2FA: ScreenForge Labs administrative accounts cannot access the admin console without an enrolled authenticator — enforced in code.
  • Session protections: idle auto sign-out (default 60 minutes, adjustable 15 min–4 h, never fully off), a 12-hour absolute cap on staff sessions, one-click “sign out of all devices,” and per-user sign-in history (time, IP, device).
  • Role-based access: Owner, Admin, and Coordinator roles scope who can manage billing, settings, and screening.

API & integration security

  • Biometric identity verification required: before any organization can use the API or MCP (AI) integration — even a single call — an owner or admin must verify their identity with a government-issued photo ID and a live selfie match. We know who is behind every integration.
  • Hardened credentials: API keys are shown once and stored only as bcrypt hashes; MCP connections use OAuth 2.0 with PKCE and SHA-256-hashed, expiring, revocable tokens; webhooks are HMAC-SHA256 signed.
  • Watched around the clock: every API/MCP call is logged with full attribution, rate-limited per caller, and swept every 15 minutes by automated abuse detection — with an instant kill switch if something looks wrong.

Encryption & data handling

  • Encrypted in transit and at rest: TLS on every connection with a two-year HSTS policy, and provider-managed AES-256 encryption at rest on SOC 2-audited infrastructure.
  • Social Security numbers get extra care: an additional layer of application-level encryption in transit, automatic stripping from URLs, hard refusal in chat/AI, and sanitized logging on sensitive paths.
  • Reports and media protected: report PDFs are password-protected; identity documents and media live in private storage reachable only via short-lived signed URLs; database access is scoped with row-level security.
  • Payments never touch our servers: Stripe (PCI DSS Level 1) handles all card data.

Accountability & monitoring

  • Append-only admin audit log: every privileged action by our staff — including support access to customer accounts — is permanently recorded and cannot be edited or deleted from the application.
  • Risk monitoring: automated account-risk holds, API abuse alerting, hardened security headers on every response, and a public status page at status.volunteerbadge.com.

Volunteer privacy commitments

  • The badge is status-only: a shared VolunteerBadge shows active/expired and validity dates — never the underlying report. Reports are visible only to the organization that ordered the check.
  • Health records and character references stay separate from the background check and are never part of a consumer report.
  • We never sell data. Volunteer and organization data is used to deliver the service — not sold, rented, or shared for advertising.

Have a security question or a vendor questionnaire?

Email support@screenforgelabs.com or call (239) 219-0929 — we complete security questionnaires for evaluating organizations. Found a vulnerability? Report it to the same address; we investigate good-faith reports promptly and never pursue legal action against good-faith research. Deeper screening-coverage detail lives in the Trust Center.
Didn't find what you needed? Email support@screenforgelabs.com or browse all articles.