The data VolunteerBadge handles — background-check reports, identity documents, and volunteers' personal information — is among the most sensitive a nonprofit will ever entrust to a vendor. We take both data privacy and security seriously so that volunteers and nonprofit leaders are fully protected. This page summarizes every measure in effect; the same content, in a board-ready document, is available below.
📄 Security Posture & Data Protection Overview (PDF)
The full 10-page document — ready to forward to your board, IT team, or security reviewer.
Download the PDF →Regulatory & FCRA compliance
- FCRA-regulated screening: ScreenForge Labs, LLC operates VolunteerBadge as a consumer reporting agency regulated under the federal Fair Credit Reporting Act. Compliance is enforced by the workflow itself, not left to memory.
- Consent first, always: no check runs without the volunteer's standalone FCRA disclosure and signed authorization, and organizations certify their permissible purpose.
- Human review of every potential record: reports with possible records are never released automatically — a trained reviewer confirms the record truly belongs to the applicant first.
- Built-in adverse action: pre-adverse notice with the report and CFPB “Summary of Your Rights,” a 5+ business-day waiting period, then the final notice — every step logged in an exportable audit trail. Volunteers can dispute report accuracy, triggering reinvestigation.
- Non-conviction protections: clear reports exclude records older than 7 years, arrests without conviction, warrants, and dismissed cases.
Sign-in & account security
- Two-factor authentication: TOTP codes from any authenticator app, enforced server-side on every page and API route — a stolen password alone opens nothing. Owners can require 2FA for their whole team.
- Mandatory staff 2FA: ScreenForge Labs administrative accounts cannot access the admin console without an enrolled authenticator — enforced in code.
- Session protections: idle auto sign-out (default 60 minutes, adjustable 15 min–4 h, never fully off), a 12-hour absolute cap on staff sessions, one-click “sign out of all devices,” and per-user sign-in history (time, IP, device).
- Role-based access: Owner, Admin, and Coordinator roles scope who can manage billing, settings, and screening.
API & integration security
- Biometric identity verification required: before any organization can use the API or MCP (AI) integration — even a single call — an owner or admin must verify their identity with a government-issued photo ID and a live selfie match. We know who is behind every integration.
- Hardened credentials: API keys are shown once and stored only as bcrypt hashes; MCP connections use OAuth 2.0 with PKCE and SHA-256-hashed, expiring, revocable tokens; webhooks are HMAC-SHA256 signed.
- Watched around the clock: every API/MCP call is logged with full attribution, rate-limited per caller, and swept every 15 minutes by automated abuse detection — with an instant kill switch if something looks wrong.
Encryption & data handling
- Encrypted in transit and at rest: TLS on every connection with a two-year HSTS policy, and provider-managed AES-256 encryption at rest on SOC 2-audited infrastructure.
- Social Security numbers get extra care: an additional layer of application-level encryption in transit, automatic stripping from URLs, hard refusal in chat/AI, and sanitized logging on sensitive paths.
- Reports and media protected: report PDFs are password-protected; identity documents and media live in private storage reachable only via short-lived signed URLs; database access is scoped with row-level security.
- Payments never touch our servers: Stripe (PCI DSS Level 1) handles all card data.
Accountability & monitoring
- Append-only admin audit log: every privileged action by our staff — including support access to customer accounts — is permanently recorded and cannot be edited or deleted from the application.
- Risk monitoring: automated account-risk holds, API abuse alerting, hardened security headers on every response, and a public status page at status.volunteerbadge.com.
Volunteer privacy commitments
- The badge is status-only: a shared VolunteerBadge shows active/expired and validity dates — never the underlying report. Reports are visible only to the organization that ordered the check.
- Health records and character references stay separate from the background check and are never part of a consumer report.
- We never sell data. Volunteer and organization data is used to deliver the service — not sold, rented, or shared for advertising.
Have a security question or a vendor questionnaire?

