Appearance
Controls v3.9
Last updated: September 30, 2026
AI4Love does not hold its own SOC 2 or ISO 27001 certification. Penetration testing is on the roadmap. Provider attestations and the DPA template are available through Requests & Contact.
This page lists each control in one place and links to the page that documents it. Controls in the first section run in AI4Love's own code and process. Controls in the second section come from the providers AI4Love builds on.
Owned by AI4Love
| Control | What it does | Documented at |
|---|---|---|
| Per-organization base isolation | Each organization gets its own Airtable working base, its own credentials, and its own access keys. No shared tenancy at the data layer. | Data Handling |
| Read-only source integrations | Blackbaud, Mailchimp, and Environics are read-only. AI4Love never writes back. Writes to the working base are limited to insight, enrichment, and campaign workflow fields by application code. | Security Controls |
| Credential storage in Nango | OAuth tokens are stored and encrypted by Nango, a dedicated credential vault. AI4Love application servers never persist tokens to disk. | Data Handling |
| Secrets in Doppler | API keys and the Airtable service account token are stored in Doppler. Keys are never committed to code or logs. | Data Handling |
| Passwordless, invite-only authentication with 24-hour sessions | Clerk sends a one-time code to the staff member's work email; there are no passwords. The backend then issues an AI4Love JWT with a 24-hour expiry. No client passwords or directory credentials are held. | Security Controls |
| Content Integrity Policy (v2026-09-09) | Prepended to every agent prompt and every campaign generation call. It prohibits inventing names, programs, outcomes, quotes, or statistics not present in the provided data, and prohibits inferring a condition, diagnosis, or personal reason behind a gift from its fund or campaign designation. | AI Behavior |
| Post-generation metric verification | After an insight is written, the verify endpoint compares AI-claimed metrics against actual supporter data and badges each new insight as verified, mismatch, or unverifiable. A safety net, not a gate. | AI Behavior |
| Action generator validation | Dashboard campaign, message, thank-you, and re-engagement outputs pass through validateActionData(). Invented supporters are stripped and counts are corrected server-side. | AI Behavior |
| Suppression before any LLM call | Eligibility filters and minimum activity thresholds run first. If pattern detection finds nothing, the LLM is never called. | Failure Modes |
| Deterministic pattern detection | Pattern detection is rollups, formulas, and thresholds. The same inputs always produce the same outputs. | AI Behavior |
| Read-only MCP | All 40 authenticated MCP tools are read-only by behavior; no MCP tool creates, modifies or deletes data, and the only OAuth permission is read. Every request resolves to exactly one organization. | MCP Access Model |
| Application rate limiting | Global 200 requests per minute, auth routes 10 per minute, API routes 60 per minute. MCP applies tool-specific response bounds only. No fixed per-key quota is enforced in application code today; per-key call volume quotas are available at the Vercel layer on request. | Security Controls |
| Audit logging | Backend [audit] and MCP [MCP] events plus request metadata: one day in Vercel, 30 days in Axiom. Staff email is the dashboard/API actor identifier; no supporter data in the stream. Clerk records authentication events, failed one-time-code attempts, device and IP metadata. Working-base Access Log is planned before first client go-live. Dashboard/API lines were absent February 14–September 9, 2026, restored September 9; MCP unaffected. Log Drain added September 14 for backend and MCP only. | Security Controls |
| Suppression mirrored from the source | Do-not-contact and no-solicitation codes carry over on the nightly sync, are enforced server-side before any model call, and close open insights for the person. | |
| Identity follows the source | The source constituent/record ID is the primary matching key, email the fallback. Email changes update the record in place; duplicates are merged with suppression flags preserved and merges logged. | Security Controls |
| Incident response timeline | Containment within 4 hours of detection. Notification within 72 hours of a confirmed breach involving customer data. Investigation within 7 days. Remediation within 14 days. | Failure Modes |
| Bounded Retention | The working base exists only while service is active, plus a 90-day exit window, then it is deleted. A full export or immediate deletion is available on request. Source-system deletions and merges are removed on request within 5 business days with written confirmation during pilot phase. | Data Handling |
| Revocation | Disconnecting an integration or removing an API key stops new requests immediately; stateless calls revalidate credentials every time. An assistant signed in to MCP with OAuth stops at its next token refresh, within 30 minutes. | Data Handling |
| Data classification | AI4Love does not require and does not process protected health information, financial account or card data, government-issued identifiers, or biometric data. | Overview |
Inherited from providers
| Control | What it does | Documented at |
|---|---|---|
| Encryption in transit (TLS 1.2+) | All API calls, webhook payloads, OAuth flows, and MCP queries. No plaintext connections accepted. | Data Handling |
| Encryption at rest (AES-256) | Stored data in Airtable, OAuth tokens in Nango, secrets in Doppler, and build artifacts and environment variables in Vercel. | Data Handling |
| SOC 2 Type II attestations | Airtable, Vercel, Nango, Doppler, and Clerk each hold SOC 2 Type II. AI4Love can facilitate access to provider reports under NDA. | Sub-Processors and Requests & Contact |
| Physical and network security | AI4Love does not operate its own data center infrastructure. Hosting, storage, and credential management are delegated to audited providers. | System Architecture |