Trust · Security
Security
This page describes how the shared record is protected. It is written for trustees, grants managers and IT reviewers, and every control on it exists in the product today. When something changes, this page changes with it.
Where data lives
Grantary is operated by PRODRO GROUP LIMITED, a UK company. Grant records, documents, ledgers and the audit trail are stored and processed in Frankfurt, Germany, so they do not routinely leave the European Economic Area. All traffic is encrypted in transit (TLS 1.2 or later). Data is encrypted at rest and backed up by the managed database provider.
Accounts and sessions
- Two locks on every account: a password and a mandatory authenticator app code. There is no way to opt out of the second factor.
- Passwords are stored only as salted hashes. Ten failed sign-ins lock the account for fifteen minutes.
- Sessions are server-side and revocable. They expire after two hours of inactivity, and changing or resetting a password signs the account out everywhere.
Who can see what
Every grant record has two sides, the funder and the recipient, with permissioned views of the same underlying record. Every read and write passes one server-side authorisation check of the caller’s side, membership and permission. Permissions are explicit per person: what an administrator sees in the permission checkboxes is exactly what the server enforces. Viewers, auditors and trustees can be added at no cost and see exactly what they are given access to, nothing more. Auditor accounts are read-only by design.
What is logged
Every change on a grant is written to an append-only history in the same database transaction as the change itself, with who, what and when, each entry chained to the one before. The database refuses to update or delete that history outright, a rule that binds us as much as anyone. Evidence files are locked the moment they are uploaded: a fingerprint is taken at upload and checked every time the file is served. The history is what the audit pack is built from, and the pack format is published so an auditor can verify a record without an account.
Certification status
PRODRO GROUP LIMITED is registered with the Information Commissioner’s Office, registration number ZC244900. Grantary does not currently hold Cyber Essentials or ISO 27001 certification. If that changes, this page will say so. No payment card details touch our systems: card payments are taken by Stripe on its own pages, and grant money is tracked here, never moved.
Sub-processors
The third-party providers that run Grantary. Each one is in the serving path today. A new or replacement provider is listed at least 30 days before it first processes customer data. The live list, with the transfer safeguard for each provider, is kept at app.grantary.co.uk/subprocessors.
- Vercel Inc. Application hosting and compute. United States company; compute runs in Frankfurt, Germany.
- Prisma Data, Inc. Managed PostgreSQL database holding all application records, including evidence file content. United States company; storage in Frankfurt, Germany.
- Resend, Inc. Transactional email: verification codes, invitations, digests and notifications. United States company.
- Stripe Payments Europe, Ltd. Subscription billing for organisations on paid plans. Card details are collected and held by Stripe and never touch Grantary. Irish company, part of the Stripe group.
Companies House and the charity regulators are public registers we query to verify organisation details. They are independent public bodies, not processors acting for us.
Incident response
If a personal-data breach affects a customer’s data, we notify that customer without undue delay, with the information their own 72-hour ICO obligation needs. The commitment is contractual, in the Data Processing Agreement. The product also gives each organisation its own serious-incident register, so its notification duties to funders are recorded facts, not recollections.
Reporting a concern
If you believe you have found a security problem, write to hello@grantary.co.uk with “Security” in the subject line. A person replies within one business day. We read every report and will not take action against good-faith research. Please do not access data that is not yours, degrade the service, or publish details before we have had a reasonable chance to fix the issue.
Mirrors app.grantary.co.uk/security and /subprocessors, checked 15 September 2026. The app pages are the live versions.
Anything unclear? Ask us.
We answer questions about security, data and the audit pack directly. We reply to every enquiry, usually within one working day.