Support Center›Security & Privacy›Security Best Practices

Security Best Practices

How to keep your DonorDesk account secure.

Practical steps to keep your DonorDesk workspace safe.

Accounts and passwords

  • Use a long, unique password for DonorDesk and store it in a password manager. Change it in Settings → Security.
  • Never share a login. Invite each person with their own role.
  • Sign out on shared computers.
  • DonorDesk does not currently offer two-factor authentication, so protect the email account tied to your login (it is used for password resets) and, if you use Google sign-in, enable 2-step verification on your Google account.

Give the least access needed

  • Use Viewer for board members, donors and auditors; Field Officer for people who only log activities and evidence.
  • Keep the Admin role to a small number of trusted people (at least two, so you are never locked out).
  • Review the Team page regularly and change roles when people move on.
  • Assign people only to the projects they work on.

Handle sensitive evidence carefully

  • Set Confidentiality correctly when you upload: Public, Internal, Sensitive or Highly sensitive.
  • Beneficiary lists, case files, medical or protection records should be Sensitive or Highly sensitive. They are kept out of AI drafts and need explicit approval before export.
  • Keep original sensitive files in your own Google Drive with restricted sharing.
  • Do not paste personal data into report text or the Ask AI box.

Google Drive

  • Use a dedicated organisational Google account to connect Drive, not a personal account.
  • Review who has access to your DonorDesk folders in Drive.

Reports and exports

  • Use the watermarked internal copy for internal circulation and the donor submission export only after approval.
  • Check the export gate's confidentiality items before sending anything outside.
  • Store exported files safely; downloads are your responsibility once they leave DonorDesk.

Watch for problems

  • Use Settings → Audit log to review unexpected changes.
  • If you think an account was compromised, change the password, tell your Admin and email support@donordesk.online.