Demo environment — every organisation here is fictional, and the whole world resets nightly. Explore freely; nothing you do is kept.

Security

How Grantary protects the records it keeps. Last updated 29 July 2026. Everything on this page describes controls that exist in the product today.

Accounts and sessions

  • Two locks on every account: a password and a mandatory authenticator app (TOTP). There is no way to opt out of the second factor.
  • Passwords are stored only as salted scrypt hashes; authenticator codes are replay-guarded; ten failed sign-ins lock the account for fifteen minutes.
  • Sessions are server-side and revocable: they expire after two hours of inactivity (30-day hard cap), and changing or resetting a password signs the account out everywhere. Password reset links are single-use, expire in 30 minutes, and are stored only as hashes — and they never reset the authenticator, so an email inbox alone can't unlock an account.

Access control

  • Every grant spans exactly two organisations — the funder and the recipient — and every read and write passes a single server-side authorisation choke point that checks the caller's side, membership and permission.
  • Permissions are explicit per person (17 keys); what an administrator sees in the permission checkboxes is exactly what the server enforces. Auditor accounts are read-only by design.
  • Sharing beyond a grant record (the organisation passport) is granted by the charity, scoped, revocable, and audited.

Record integrity — the part that makes Grantary Grantary

  • Write-once evidence: file bytes never change after upload. Every file is SHA-256 hashed at upload and the hash is re-verified every time the file is served — a byte out of place is an error, never silence.
  • Append-only audit trail: every change writes an audit event in the same database transaction as the change itself, each event hash-chained to the one before. The database refuses UPDATE and DELETE on the trail outright — a protection that binds us too, not just users.
  • The audit-pack export format is publicly specified, so anyone can verify an exported record's integrity without a Grantary account.

Infrastructure

  • All traffic is encrypted in transit (TLS 1.2+).
  • Data is encrypted at rest and backed up by our managed database provider; the current provider list, with locations stated honestly, is at /subprocessors.
  • Secrets (API keys, tokens) are never hardcoded; operator-managed keys are masked in the console and excluded from audit payloads.

Incidents and breach notification

If a personal-data breach affects a customer's data we notify them without undue delay with the information their own 72-hour ICO obligations need — the commitment is contractual, in the Data Processing Agreement. The product also gives organisations their own serious-incident register, so their notification duties to funders are provable facts.

Reporting a vulnerability

If you believe you've found a security problem in Grantary, tell us at info@prodro.co.ukwith "Security" in the subject line. We read every report, we'll acknowledge yours promptly, and we won't take action against good-faith research — please don't access data that isn't yours, degrade the service, or publish details before we've had a reasonable chance to fix the issue.

What we don't claim

Grantary does not currently hold Cyber Essentials or ISO 27001 certification — if that changes, this page will say so. And no payment card details touch our systems: money is tracked here, never moved.