Skip to main content

Security Overview

Last updated August 22, 2026

Put It Forward, Inc., a Delaware corporation with its principal place of business in Austin, Texas, adopts industry-standard frameworks to manage our information security program. This program is designed to protect Put It Forward's and our customers' data security and privacy.

Our security priorities are focused on risk management best practices, regulatory and contractual compliance, enabling safe innovation, and increasing customer trust. This page summarizes those practices. Security commitments specific to your organization are governed by your Master Services and Software Agreement ("MSSA") and any applicable Data Processing Addendum.

Security by Design

Security is built into the platform architecture at every layer — network transport, application logic, data processing, and physical infrastructure — and is reviewed on an ongoing, continuous basis as part of our security program.

Our Role as a Sub-Processor

Put It Forward operates as a sub-processor to our customers, who remain the data controllers and data managers responsible for their own regulatory and compliance obligations, including any SOC, ISO, or other certifications applicable to their organization. Put It Forward does not itself hold SOC or ISO certifications, as our role in the data relationship is to process and support customer data under the instructions, security requirements, and compliance obligations established by each customer.

We support our customers' own certification and audit programs by completing security questionnaires, providing documentation of our internal controls, and participating in customer-led security assessments as required under the applicable MSSA and Data Processing Addendum.

Information Security Program

Put It Forward maintains internal information security policies and procedures structured to align with the ISO 27001 control framework and the NIST Cybersecurity Framework (NIST CSF). These policies cover:

  • Access management and least-privilege controls
  • Change management
  • Incident response and breach notification
  • Vendor and third-party risk management
  • Data handling, retention, and secure disposal

Data Processing and Storage

Put It Forward's platform provides decision intelligence, data science, and automation capabilities, which may include the integration and movement of data between customer systems. How and where customer data is processed and stored depends on the specific services a customer has contracted for, as set out in that customer's Order and Data Processing Addendum.

In general:

  • Data in transit is encrypted using current industry-standard encryption protocols.
  • Data at rest, where persisted at a customer's request or configuration, is encrypted using industry-standard methods.
  • Customer data is retained only as necessary to provide the contracted service, or as otherwise specified in the customer's Order.

Specific technical implementation details, including encryption standards in use, are available to customers under NDA through the security questionnaire and review process defined in your MSSA.

Access Controls

Put It Forward maintains technical and administrative access controls designed to limit employee access to customer data to what is necessary to operate, support, and secure the platform. Access to customer data outside the ordinary course of providing the service — for example, in response to a valid legal request — is subject to internal approval and is documented.

Backups and Availability

Configuration data, business rules, user profiles, and any persisted customer data are backed up in accordance with our internal backup and disaster-recovery procedures. Enterprise customers may request specific availability and recovery-time commitments through their MSSA or Order.

Third-Party Applications

If you access the Put It Forward platform through a third-party application, that application's own security and privacy practices apply to any data processed through it. Review the third-party application's terms before connecting it to your account.

Compliance with Legal Requests

Put It Forward cooperates with valid legal process from United States law enforcement and other authorities, consistent with our Privacy Policy and applicable law. We disclose customer data in response to legal process only as required, and only to the extent required.

Reporting a Security Concern

If you believe you have identified a security vulnerability in the Put It Forward platform, please report it to This email address is being protected from spambots. You need JavaScript enabled to view it.. We investigate all reported security issues and will acknowledge receipt of your report.

Questions

For security documentation, questionnaire completion, or contract-specific details, contact This email address is being protected from spambots. You need JavaScript enabled to view it. or your Put It Forward account representative. Security terms specific to your organization are governed by your MSSA and applicable Order.