generated: '2026-09-12' method: probed source: https://trust.givebutter.com/ description: >- Givebutter runs a public Trust Center on its own subdomain, hosted on Vanta. It was probed live (HTTP 200, title "Givebutter Trust Center", canonical https://trust.givebutter.com). The page is a React application that loads its control and certification data client-side, so the individual certifications listed inside it could NOT be read by a non-browser client and are deliberately not asserted here. trust_center: url: https://trust.givebutter.com/ status: 200 checked: '2026-09-12' platform: Vanta resources_url: https://trust.givebutter.com/resources machine_readable: false note: JS-rendered; no anonymous JSON surface found for the control/certification list. certifications: - name: PCI DSS held_by: Stripe (payment processor), not Givebutter directly evidence: https://givebutter.com/trust-and-safety quote: Our PCI-compliant payment processing partner, Stripe, not only securely holds donor funds verified: true unverified: - SOC 2 - ISO 27001 - HIPAA - FedRAMP note_on_unverified: >- These frameworks are NOT claimed by Givebutter on any surface this pass could read. They are listed only to record that they were looked for and not found — absence here is a measurement, not a negative finding about the company. related_pages: - url: https://givebutter.com/trust-and-safety status: 200 title: Givebutter Trust & Safety names: Stripe (PCI-compliant processing), Fifth Third Bank N.A. (funds), Celtic Bank (Wallet Visa issuing) - url: https://givebutter.com/privacy status: 200 title: Privacy Policy vulnerability_disclosure: published: false checked: '2026-09-12' probes: - url: https://givebutter.com/.well-known/security.txt status: 404 - url: https://docs.givebutter.com/.well-known/security.txt status: 404 - url: https://givebutter.com/security-policy status: 404 - url: https://givebutter.com/responsible-disclosure status: 404 - url: https://hackerone.com/givebutter status: 404 - url: https://bugcrowd.com/givebutter status: 404 note: >- No security.txt, no disclosure policy page and no public bug-bounty program was found. The trust-and-safety page routes security concerns to the general contact form. This is a real, fixable gap for a platform that moves donor funds — no separate vulnerability-disclosure artifact is written, because there is nothing published to record. maintainers: - FN: Kin Lane email: kin@apievangelist.com