Private workspaces
Tenant permissions, database isolation and mandatory MFA.
CharityPilotSign in Your charity holds people’s trust. Here are clear answers about what protects the pilot today and what must happen before live AI is enabled.
Tenant permissions, database isolation and mandatory MFA.
Time-limited staff support, with the actor recorded.
No live AI provider receives charity records today.
Private workspaces use server-checked memberships and database row-level security. A user can only access a charity where their current role permits it. Staff support access is limited to one charity and one session, expires after 30 minutes and records the person taking the action.
Yes. Every user has seven days from their first successful sign-in to verify an authenticator. The deadline cannot be reset by signing out or changing charities. After it expires, workspace access pauses until verification is complete. Staff administration requires MFA immediately.
No live AI provider is connected today. The server’s AI endpoint is closed, and a setting or request cannot enable it. Current demo assistant experiences are guided examples. Sensitive donor, beneficiary and safeguarding information is not sent to an AI provider by Charity Pilot.
Our release policy starts with keeping identifiable and sensitive records inside the charity’s protected workspace. External AI must use only approved, minimised disclosures that pass an anonymisation review. Names, contact details, bank data, passwords, identifiers, case notes and uploaded documents must not go into external prompts. Small groups, unusual events and combinations of facts can also identify people and need disclosure controls.
No. A label or reference can still be linked back to a person. Before external AI is enabled, the disclosure process must be tested for re-identification, including small groups and repeated queries. Supplier retention, training, processing locations and contractual safeguards must also be reviewed. This release review is not yet complete.
Connections use HTTPS. The hosted pilot additionally encrypts stored email content, support reasons and fictional demo snapshots with application keys kept outside the database. Account identity and operational metadata are not all encrypted at application level. Unadapted real-record write paths remain closed while protected adapters are prepared.
Our policy prohibits using charity records for shared model training. Live AI is disabled; no provider training or retention terms have yet been approved for a production AI release. Approved supplier terms and enforcement must be in place before activation.
The pilot does not enable automated beneficiary eligibility decisions, live AI actions or email delivery. Future drafts and consequential actions must remain subject to the charity’s permissions, human review and approval process.
Charity Pilot is currently an invitation-only pilot with a fictional interactive demo. Real-charity onboarding requires a recorded privacy review and release checks, including security, processing terms, retention, recovery and migration reconciliation. The public demo must never contain confidential records.
Last reviewed: 4 October 2026. These answers describe the pilot and its release policy; they are not a security certification. Read our privacy information.