Industries
A nonprofit holds donor records, payment details and often information about vulnerable people, with a fraction of the staff and none of the slack. The obligations do not scale down to match the budget. What can change is how much you pay to meet them, and how much of it you have to think about.
The reputational maths here is unusual. A business that suffers a breach loses customers. An organisation that exists on trust and voluntary giving can lose the thing that makes it viable.
Nonprofits are rarely regulated as an industry, which leads people to assume there is nothing to meet. The obligations arrive by other routes.
Any organisation that stores, processes or transmits cardholder data falls within the scope of PCI DSS. It is enforced through your acquirer or payment brand agreement rather than by statute, which means the obligation is contractual and real. The cheapest way to meet it is almost always to arrange things so your systems never touch card data at all.
Grant agreements and institutional funders increasingly include security and data-handling terms, and questionnaires that expect specific answers. These arrive with a deadline attached and are far easier to answer when the controls already exist.
Organisations running youth, health, housing or counselling programmes hold sensitive personal information about the people they serve, and sometimes fall under sector rules as a result. Faith-based organisations often hold pastoral and safeguarding records with no formal classification at all, which does not make them less sensitive.
Most nonprofits publish a privacy commitment to donors. That is a statement you can be held to, and it is worth knowing whether your systems actually support it.
All included in the monthly rate. The two that matter most for a nonprofit are unglamorous.
The same published rates apply, and we do not run a separate nonprofit price list — the published one is already the price. $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month, or $199 for a fully equipped seat. No minimum, no setup fee, no automatic annual escalator, so an organisation with eight staff pays for eight. The pricing page has a calculator.
We support organisations across Northeast Ohio and the Greater Houston area. Iconium’s founder serves on local nonprofit boards, which is the main reason this is a category we know rather than a category we list.
There is no minimum here, no seat minimum and no setup fee, so an organisation with eight staff pays for eight. We also do not operate a separate nonprofit rate card, because the published rate is already the rate — you can see it without asking. Where we genuinely save nonprofits money is elsewhere: the nonprofit pricing and grant programmes the major software vendors run, which change often enough that most organisations are either missing them or still assuming an old one applies.
By making offboarding a step rather than an intention. Named accounts instead of shared logins, a documented process when someone leaves, and access reviewed on a schedule so the list is checked by someone rather than accumulating quietly. This is the single most common gap we find in nonprofits and it is also one of the cheapest to close.
Layered, and the last layer is not technical. Email security and quarantine catch most impersonation attempts before anyone sees them. Multi-factor authentication means a stolen password is not enough on its own. Simulated phishing means the person on the receiving end has seen the pattern in a safe setting. Then a callback rule on a known number for any payment change, which we will help you write but your team has to actually follow — and the board should back them when they use it on the director.
You are in scope if your systems store, process or transmit cardholder data. The useful move is to arrange things so they do not: a hosted donation page or a redirect keeps the card data with the processor and keeps your scope as small as it can be. The obligation reaches you through your acquirer or payment brand agreement rather than through a statute, so check what yours says. We help with the arrangement; we do not assess or certify compliance.
We can tell you exactly what is deployed and show the evidence behind each answer, which is the hard part. The form goes in over your organisation’s signature because the funder is contracting with you. Send it over before the deadline rather than the week of it — these questionnaires usually surface one or two things worth fixing first, and a fixed answer is better than an explained one.
Mostly, with one difference worth naming. Congregations hold pastoral, membership and often youth programme records that carry no formal regulatory classification, which sometimes leads to them being treated as less sensitive than they are. A membership directory with addresses and family details is a valuable file, and a safeguarding record is a serious one. The controls are the same; the conversation about what you hold is worth having explicitly.
With an inventory, and without blame — this is extremely common and it is not anyone’s failure. We work out what exists, what it does, who has access and what nobody has the password for. That last category is usually the urgent one. From there it is a prioritised list rather than a rebuild, and most organisations need far less replaced than they fear.
We plan for a clean handover and never withhold data or organisational intellectual property. We work with whoever comes next, including a volunteer, and we hand over documentation rather than a shrug. Onboarding in the other direction takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.
Call (440) 991-9980 or book a thirty minute call. For most organisations that one question opens the whole conversation, and the answer is usually fixable in an afternoon.
See also: every industry we serve and our written answers.