Security

Your grant data is sensitive. We treat it that way.

Cardholder data, transaction records, and grant information are held to strict data handling practices. Here is what we do, in plain language.

Data Practices

How we handle cardholder and transaction data

We collect only what is required to operate the card program and provide grant compliance reporting. We do not sell data or use it for advertising.

Encryption in transit and at rest

All data in transit uses TLS 1.3. Transaction records and cardholder data stored on our platform are encrypted at rest using AES-256.

Card data handled by our banking partner

Primary card account numbers (PANs) and full magnetic stripe data are handled by our banking partner's PCI-compliant infrastructure. KleerCard systems store only truncated card numbers.

Access controls

Platform access is separated by organization. Internal KleerCard staff access to customer data is role-based and logged. Finance directors control which staff can view card and transaction data within their account.

Infrastructure

KleerCard runs on AWS in the US region. We do not transfer customer data outside the United States for processing or storage during normal operations.

Retention and deletion

Transaction data is retained for seven years to support grant audit requirements. After account cancellation, data enters a 30-day export window before deletion per our data retention policy.

No data selling

We do not sell, license, or share your transaction or organizational data with third parties for marketing or advertising purposes. Data is shared only with service providers necessary to operate the platform.

Card Program

Card security is handled at the network level

Abstract security diagram showing layered card authorization and fraud detection

Physical cards include EMV chip technology. Virtual cards use tokenized card numbers valid only for authorized use cases.

Fraud monitoring is managed by our banking partner using network-level transaction analysis. Suspicious transactions are flagged or blocked before authorization completes.

Cards can be frozen or permanently disabled from the KleerCard dashboard by finance directors instantly, with no phone call required.

Grant policy controls (merchant category restrictions, spending limits) serve as an additional layer. A card restricted to educational supplies cannot be used at restaurants, regardless of other controls.

Spend Controls

Controls built into the card, not the review process

Merchant category restrictions

Define which merchant category codes are allowed on each card. A grant restricted to program expenses can block entertainment, travel, and office supply categories from the card level.

Spending limits per card

Set per-transaction and monthly spending limits. If a single purchase exceeds the configured limit, it is declined or flagged for approval before processing.

Grant period enforcement

Set grant period end dates. Cards assigned to a grant with an expired period are automatically restricted from new charges, preventing post-period overspending. Available on Organization tier.

Compliance Roadmap

Where we are heading on certifications

We are an early-stage company. Here is an honest picture of our compliance posture today and what we are working toward.

In Place Now
PCI compliance via banking partner
Card data handling follows PCI-DSS requirements through our banking partner's infrastructure. KleerCard does not store PANs or full card data on our systems.
In Place Now
TLS 1.3 and AES-256 encryption
All data in transit and at rest is encrypted. AWS infrastructure in US region.
Roadmap Goal
SOC 2 Type II audit
We are building toward a SOC 2 Type II audit as a planned goal once we have completed a full 12-month operational period. We do not hold SOC 2 certification today.
Roadmap Goal
Penetration testing program
Formal third-party penetration testing is planned for 2026 as we approach general availability and expand the customer base.
SOC 2 and penetration testing are planned goals, not certifications we hold today. We believe nonprofits deserve an accurate picture of the security posture of tools they trust with grant data.
Questions?

Have a specific security question before you commit?

We are happy to answer detailed questions about our data practices, infrastructure, or card program before you sign up. Email us directly.