π Transparency Dashboard
We don't just promise privacyβwe prove it. See exactly how we handle your data with monthly reports, security scans, and compliance metrics.
Our Zero Spam Guarantee
No Email Spam
Only grant matches and deadline reminders you opt into
No Data Selling
We will NEVER sell your data to third parties
GDPR/CCPA Ready
Built for compliance from day one
Monthly Reports
Published openly for full transparency
Monthly Transparency Reports
January 2025
LatestPublished: January 1, 2025
February 2025
Report will be published February 1, 2025
March 2025
Report will be published March 1, 2025
Security & Encryption
Encryption in Transit
Encryption at Rest
Access Controls
Monitoring & Logging
Automated Security Scanning
All Scans Passed
Last run: December 14, 2025 β’ Runs before every deployment
| Security Check | Tool | Results | Status |
|---|---|---|---|
| Secret Detection | Gitleaks | 149 commits scanned, 0 secrets found | β Passed |
| Static Analysis (SAST) | Semgrep | 198 security rules, 0 critical findings | β Passed |
| Dependency Vulnerabilities | Trivy | 0 high/critical vulnerabilities | β Passed |
| Database Security | Supabase Test | 258 tests passed, no schema errors | β Passed |
| Code Quality | Biome (Ultracite) | Linting & formatting enforced | β Passed |
Continuous Security: These scans run automatically on every git commit via pre-push hooks, and again before every deployment. Failed scans block deployment until issues are resolved.
Compliance & Standards
GDPR Ready
- β Data protection by design
- β 72-hour breach notification
- β Right to deletion & portability
- β Privacy impact assessments
CCPA/CPRA Compliant
- β No data sales (ever)
- β Enhanced protections for minors
- β Opt-out mechanisms
- β Annual privacy audits
COPPA Compliant
- β Age verification required
- β Parental consent (ages 13-15)
- β No accounts under 13
- β Enhanced student protections
State Privacy Laws
- β Virginia VCDPA
- β Colorado CPA
- β Connecticut CTDPA
- β Universal opt-out (GPC)
Security Standards
- β OWASP Top 10 coverage
- β SOC 2 Type II (in progress)
- β NIST framework alignment
- β Regular penetration testing
Transparency
- β Monthly public reports
- β Open-source security configs
- β Real-time status page
- β Incident disclosure policy
Privacy & Security Updates
Read our latest posts about privacy, security, and how we're building a trustworthy platform:
View Privacy & Security Blog βHow We're Different
π Privacy by Design
We built privacy into our architecture from day one, not retrofitted it later. Row-level security, encryption, and access logging are core features.
π Radically Transparent
We publish monthly reports showing exactly how many emails we send, data requests we handle, and security scans we run. No hiding.
β User Control
You control what emails you receive, when, and how often. Export or delete your data anytime. No hoops to jump through.
π― Student-First
We're here to help students find funding, not to sell their data. Our business model is subscriptions, not surveillance.
Questions About Privacy?
We're committed to being transparent and answering your questions. Read our privacy policy or reach out directly.