Find, vet, and fund
the right nonprofits.

The prospecting & due-diligence platform for grantmakers - built on robust, authoritative data sources covering $1.2T+ in grant flows.

Try Discover free →
$1.2T+
Grant flows tracked
450+
Attributes / org
Nightly
Data refresh
Backed by
Blackbaud
Social Good Startup Program
Designed for teams at
DAF Sponsors
Community Foundations
Private Foundations
Grant Management Software
Workplace Giving Platforms
Retail Fundraising Platforms

Finding and vetting the right nonprofits is slow and manual

Grantmakers lose thousands of hours every year hunting for the right organizations and piecing together the data to vet them - from filings to sanctions lists to the open web. What exists is scattered, archaic, and doesn't surface what matters for a confident funding decision.

🧩

Data is scattered and unstructured

What you need is spread across IRS filings, sanctions and watchlists, watchdog sites, and the open web - most of it raw and unstructured. Pulling it into one place takes months of manual work or engineering.

⏱️

Manual verification across sources takes hours

Checking eligibility, revocation, sanctions, and governance means juggling separate websites and running searches by hand for every organization - and re-doing it all whenever something changes.

💸

Existing solutions are archaic and expensive

The legacy providers in this space were built decades ago. Their data is often stale and incomplete, their tools are clunky, and their pricing was designed for legacy institutions - not modern grantmakers and platforms.

Comprehensive prospecting & due diligence, made easy

The web app for grantmaking teams. Sign up in less than 2 minutes and search 1.9M+ nonprofits and the funders behind them, vet any organization, get a holistic understanding of all their operations, and turn raw data into decisions.

🔍

Find

Prospecting

Search by cause, geography, size, financials, growth, and who-funds-whom. Ask in plain English and build exportable shortlists in seconds.

🛡️

Vet

Due diligence

Check IRS eligibility, revocation, sanctions, governance and risk signals before money moves - the full picture in one view.

📈

Analyze

Intelligence

Turn raw 990 filings into structured insight on finances, leadership, programs and multi-year trends - ready for reports and decisions.

Try Discover free →

Free to start · Pro trial available - no credit card required

Power your product with nonprofit intelligence

The same authoritative data behind Discover, delivered as fast, structured APIs - so platforms and teams can verify, enrich, and prospect right inside their own workflows.

🛡️

Verify API

Real-time eligibility & sanctions verification

Instantly verify any nonprofit's standing with a single API call - a 6-step check covering active IRS status, Pub 78 eligibility, group exemption, IRS revocation, org OFAC screening, and leadership screening, all in under 100ms.

  • Active 501(c)(3) status & Pub 78 eligibility
  • IRS auto-revocation & group exemption traversal
  • Screen charity officers & directors against OFAC SDN + Consolidated lists
  • Validate against California FTB & AG charity registries
  • Bulk Verify - up to 20K verifications for batch screening
  • Report API - generate a shareable due-diligence report
⚡ The only API that screens charity leadership, not just the org name
View API docs →
📊

Data Pro API

450+ extracted & computed attributes per organization

We parse every IRS Form 990, 990-EZ, and 990-PF filing - transforming raw XML into clean, structured JSON. Query 450+ extracted and computed attributes per nonprofit by EIN, spanning tens of thousands of underlying data points across filing years.

  • Revenue, expenses, assets & computed financial ratios
  • Officer compensation & board composition
  • Grants made & received, with funder-recipient mapping
  • Programs, mission, governance & policy signals
  • Multi-year history with growth & trend indicators
📊 450+ attributes spanning tens of thousands of data points per org
Talk to sales →

FaithVerify API

Denomination & religious organization verification

The only structured database of religious organizations that can accept tax-deductible donations. AI agents scan denominational databases and official websites to confirm legitimacy and affiliation.

  • Instant status verification of over 90% American churches
  • IRS group exemption mapping & hierarchy data
  • AI agents verify against official denominational registers
  • Active congregation status & affiliation confirmation
  • Built for DAFs, community foundations, and workplace giving platforms
🤖 AI agents scan denominational directories and church websites to verify 501(c)(3) equivalency.
Talk to sales →
1.9M+
Nonprofits Verified
3.6M+
Grants Mapped
1.3B+
Structured Data Points
<100ms
Avg. API Response Time

From EIN to full verification in seconds

1

Get your API key

Tell us about your use case and we'll provision your credentials. Integrate in minutes with our REST API.

2

Send an EIN query

GET /v1/verify?ein=
Pass any nonprofit's EIN. Batch queries and webhooks supported.

3

Get structured intelligence

Receive a verified status, financial ratios, governance flags, and OFAC screening results -including all charity leaders -in one response.

4

Stay current automatically

Our pipeline refreshes nightly from 6 IRS sources via Lambda. Subscribe to webhooks for real-time change alerts.

Built for the teams that move money for good

🏦

DAFs & Community Foundations

Automate charity vetting at the point of grant recommendation. Verify active status, Pub 78 deductibility, Revocation Lists and OFAC clearance - without manual research. Scale grant processing from days to seconds.

EIN VerificationPub 78 EligibilityOFAC Screening
🏗️

Grant Management SaaS & Workplace Giving

Embed Givalgo into your grant lifecycle and employee giving programs. Surface financial ratios, governance flags, and real-time compliance status directly in your platform UI -with zero manual research required.

Financial RatiosGovernance FlagsPayroll Giving
🏛️

Private & Corporate Foundations

Surface multi-year financial trends, program expense ratios, board composition and risk-flags for every grantee. Conduct thorough due-diligence with structured data on potential grantees instead of manually going through docs.

Multi-year TrendsBoard DataProgram Ratios
💳

Fintech & Retail Fundraising Platforms

Power donation rails, matching engines, and retail giving flows with verified nonprofit data. Prevent fraud, ensure tax compliance, and pass audits confidently -all from a single API integration.

Fraud PreventionAML/KYCMatching Engines

Trusted by grantmaking and platform teams

Givalgo cut our nonprofit vetting process from several hours a day down to zero minutes. It's fully automated. The OFAC leadership screening and church verification are something we couldn't find anywhere else -it's exactly what our compliance team required.

HI
Head of Innovation
National Donor-Advised Fund

We evaluated several data providers before landing on Givalgo. The depth of the API, low price, and scalability is exactly what a modern grant management platform needs. Integration was seamless.

VP
VP of Product
Grant Management Platform

Before Givalgo, our compliance and ops team was responsible for regularly ingesting IRS and OFAC data and screening incoming grant requests - Candid was too expensive. Now the donor request is immediately approved and passed on to finance for disbursement.

HC
Head of Compliance
Workplace Giving & Payroll Platform

Building the definitive prospecting & due-diligence platform for a $600B+ sector

We're starting where the data problems are most acute. Our roadmap leads to a full-stack intelligence platform for grantmakers -eventually the trusted backbone for every philanthropic dollar that moves in America.

Live

Verify API

6-step real-time verification: active 501(c)(3) status, Pub 78 eligibility, group exemption traversal, IRS auto-revocation check, OFAC sanction checks, and leadership screening - including every charity officer and director -across 1.9M+ organizations. Includes Bulk Verify and the Report API.

Live

FaithVerify API

AI agents continuously scan 40+ denominational databases and official websites to verify religious organization legitimacy, IRS group exemption status, and congregation-level affiliation -the only structured database of its kind.

Live

Data Pro API

450+ extracted and computed attributes from every IRS 990 filing -revenue, expenses, leadership compensation, grants made and received, governance, and computed ratios. Automated Lambda + EventBridge pipeline, backed by 1.3B+ structured data points.

Live

Givalgo Discover

The web app for grantmaking teams -prospect, vet, and analyze 1.9M+ nonprofits and the funders behind them in plain English. Natural-language search, full due-diligence, financials, grants, and peer benchmarks, all in the browser.

Coming soon

Givalgo Watch

Real-time monitoring of your portfolio of nonprofits -track every organization you care about across IRS filings, sanctions lists, and the news, and get alerted the moment something changes.

Q3 2026

Givalgo AI — Autonomous Due Diligence

Point Givalgo AI at any organization and get a complete, citation-backed due-diligence brief in seconds -financials, governance, risk flags, and live web research, synthesized for you. Then ask follow-up questions in plain English.

Start free. Scale when you're ready.

Use Discover free, or talk to us about API access for your platform. Either way, you get a direct line to the founding team.

Discover
Free to start

Pro (worth $20 / mo) - 14-day trial, no credit card

The web app for grantmaking teams. Prospect, vet, and analyze nonprofits right in your browser.

  • Search 1.9M+ nonprofits & their funders
  • Ask - natural-language prospecting
  • Full verification & due-diligence
  • 5-year financials, grants & benchmarks
  • Pro free for 14 days, then $20 / mo
Try Discover free →

No credit card required

Givalgo API
Custom

For platforms & teams embedding Givalgo data. Usage-based plans, scoped to your needs.

  • Verify API - IRS, State AG & Sanctions
  • Data Pro API - 450+ attributes per organization
  • FaithVerify API - religious-org verification
  • Custom configurations & volume
  • Dedicated support & founder access
Find, vet, and fund - faster

Start with Discover free,
or build with our APIs.

Join the grantmakers and platforms that trust Givalgo to find the right nonprofits, vet them with confidence, and power their giving.

Try Discover free →

No commitment required  ·  Response within 1 business day  ·  14-day Discover trial, no card

Privacy Policy

Last updated: March 30, 2026  ·  Effective date: March 30, 2026

1. About This Policy

Givalgo, Inc. ("Givalgo," "we," "our," or "us") is committed to protecting the privacy and security of the information entrusted to us. This Privacy Policy describes how we collect, use, process, disclose, and protect your personal information when you:

  • Visit our website at givalgo.ai and related subdomains
  • Access or use our API services at api.givalgo.ai
  • Review our developer documentation at docs.givalgo.ai
  • Communicate with us via email, forms, or other channels
  • Book a demo or attend a product presentation
Important note about our data: Givalgo's core database is built entirely from publicly available U.S. government sources -IRS nonprofit filings, IRS sanctions data, and OFAC sanctions lists. We do not collect, store, or sell personal data about individual donors, nonprofit beneficiaries, or third-party individuals. All nonprofit and organizational data in our platform is sourced from public government records and processed in accordance with applicable law.

This policy applies to all users globally. Where we reference specific legal frameworks (such as GDPR or CCPA), those sections apply only to users in the relevant jurisdiction.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account, subscribe to a plan, or contact us, we collect:

  • Account Information: Full name, work email address, company name, job title, and password (stored as a salted hash -never in plain text)
  • Billing Information: Payment card details and billing address, processed and stored by our payment processor (Stripe). We do not store full card numbers on our systems.
  • Communication Data: Any messages, inquiries, or feedback you submit via email, contact forms, or demo requests
  • Demo Booking Data: Name, email, company, and any notes provided when booking a product demonstration via our scheduling system (Calendly)
  • Survey and Feedback Data: Responses to optional user research surveys or NPS feedback requests

2.2 Information Collected Automatically

When you interact with our website or API, we automatically collect certain technical data:

Data TypeExamplesPurpose
Log DataIP address, browser type, OS, referrer URL, pages visited, timestampsSecurity monitoring, debugging, analytics
API Usage DataAPI key ID, endpoint called, EINs queried, response codes, latency, request volumeBilling, rate limiting, usage dashboards, audit logs
Device InformationScreen resolution, device type, browser versionProduct improvement, compatibility
Session DataLogin timestamps, session duration, feature interactionsSecurity, product analytics

API usage logs are stored in our api_usage_log table in our PostgreSQL database, associated with your API key ID (not your personal email) to provide usage dashboards and enforce plan limits.

2.3 Information from Third Parties

We may receive limited information about you from:

  • Payment Processors (Stripe): Confirmation of payment success/failure and subscription status
  • Authentication Providers: If you sign in via SSO or OAuth, we receive your name and email from that provider
  • Referral Partners: If you were referred to us, we may receive your organization name and contact details from a mutual partner

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Providing and Operating Our Services

  • Creating and managing your account and API credentials
  • Processing payments and managing subscription plans
  • Delivering API responses and maintaining service uptime
  • Providing usage dashboards, rate limit enforcement, and billing summaries
  • Responding to support requests and technical inquiries

3.2 Security and Compliance

  • Detecting, preventing, and investigating fraudulent or unauthorized use of our API
  • Maintaining audit logs for compliance with financial regulations and AML/KYC obligations applicable to our enterprise customers
  • Protecting the integrity of our infrastructure and preventing abuse
  • Complying with applicable laws, including OFAC, AML, and IRS regulations

3.3 Product Improvement and Analytics

  • Analyzing aggregated, anonymized usage patterns to improve API performance and coverage
  • Conducting internal research on which features are most valuable to our users
  • Identifying and fixing bugs, performance bottlenecks, and data quality issues

3.4 Communication

  • Sending transactional emails: account confirmations, password resets, billing receipts, API key notifications
  • Sending product update communications and release notes (you may opt out at any time)
  • Scheduling and conducting product demonstrations

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:

Processing ActivityLegal Basis
Providing API services and fulfilling your subscriptionPerformance of a contract (Art. 6(1)(b) GDPR)
Processing paymentsPerformance of a contract
Sending transactional emailsPerformance of a contract / Legitimate interests
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f) GDPR)
Product analytics (aggregated)Legitimate interests
Marketing communicationsConsent (Art. 6(1)(a) GDPR) -you may withdraw at any time
Compliance with legal obligationsLegal obligation (Art. 6(1)(c) GDPR)

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms as a data subject.

5. Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties. We may share your information in the following limited circumstances:

5.1 Service Providers

We share data with carefully vetted service providers who process it on our behalf, subject to strict data processing agreements. Current providers include:

  • Amazon Web Services (AWS): Cloud infrastructure, database hosting (RDS PostgreSQL), file storage (S3), serverless compute (Lambda), and API Gateway. Data is stored in us-east-2 (Ohio, USA).
  • Stripe: Payment processing and subscription management. Stripe is PCI-DSS Level 1 certified.
  • Calendly: Demo scheduling. Your name and email are shared when booking a call.

5.2 Legal and Regulatory Disclosures

We may disclose your information if required to do so by law or in good-faith belief that such action is necessary to: (i) comply with a legal obligation, subpoena, or court order; (ii) protect and defend the rights or property of Givalgo; (iii) prevent or investigate possible wrongdoing in connection with our services; or (iv) protect the personal safety of users or the public.

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you via email or a prominent website notice before your personal information becomes subject to a different privacy policy.

5.4 With Your Consent

We may share your information for any other purpose with your explicit consent.

6. Cookies and Tracking Technologies

Our website uses a minimal set of cookies strictly necessary for operation:

Cookie TypePurposeDuration
Session CookieMaintains your authenticated session on the docs and dashboardSession (deleted on browser close)
CSRF TokenProtects against cross-site request forgery attacksSession
Preference CookieRemembers your UI preferences (e.g., dark/light mode)1 year
We do not use third-party advertising cookies, behavioral tracking pixels, or cross-site tracking technologies. We do not use Google Analytics, Facebook Pixel, or similar tracking services on our platform. Our analytics are entirely first-party and privacy-preserving.

7. Data Security

We take the security of your data seriously and implement multiple layers of protection:

  • Encryption in Transit: All communications between your browser/application and our servers use TLS 1.3
  • Encryption at Rest: Our RDS PostgreSQL database uses AES-256 encryption at rest via AWS
  • Secrets Management: API keys, database credentials, and service tokens are stored in AWS Secrets Manager -never in source code or environment variables
  • Network Isolation: Our database runs in a private VPC subnet with no direct internet access; only our Lambda functions (within the same VPC) can connect
  • API Key Authentication: Every API request requires a valid API key passed via x-api-key header; keys are hashed before storage
  • Rate Limiting: Per-key rate limits are enforced at the API Gateway layer to prevent abuse
  • Audit Logging: All API requests are logged with key ID, timestamp, endpoint, and response code for security monitoring
  • SOC 2 Type II: We are currently working toward SOC 2 Type II certification

While we implement industry-standard safeguards, no security system is impenetrable. We cannot guarantee the absolute security of data transmitted over the internet. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law.

8. Data Retention

We retain different categories of data for different periods based on business and legal requirements:

Data CategoryRetention PeriodReason
Account informationDuration of subscription + 3 years after closureLegal/tax obligations
Payment records7 yearsFinancial regulations
API usage logs90 days (rolling)Billing, debugging, security
Support communications3 yearsService quality, dispute resolution
Audit logs (security)1 yearSecurity monitoring
Marketing consent recordsUntil withdrawal + 3 yearsLegal compliance (GDPR)

When your account is closed or data reaches its retention limit, we securely delete or anonymize it. You may request early deletion of your personal data (subject to legal retention obligations) by contacting privacy@givalgo.ai.

9. International Data Transfers

Givalgo is incorporated in the United States, and our infrastructure is hosted in the AWS us-east-2 (Ohio) region. If you are accessing our services from outside the United States, your information will be transferred to and processed in the United States.

For users in the European Economic Area (EEA) or United Kingdom, such transfers are made pursuant to Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms. By using our services, you consent to these transfers where required.

10. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@givalgo.ai and we will promptly delete that information.

11. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@givalgo.ai:

Rights Available to All Users

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete personal data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Receive your personal data in a structured, machine-readable format
  • Opt-Out of Marketing: Unsubscribe from marketing emails at any time by clicking the unsubscribe link or emailing us

Additional Rights for EEA / UK Users (GDPR)

  • Restriction of Processing: Request that we restrict processing of your data in certain circumstances
  • Object to Processing: Object to processing based on legitimate interests or for direct marketing
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing
  • Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority (DPA)

We will respond to all verifiable requests within 30 days. In complex cases, we may extend this by an additional 60 days with notice. We will not discriminate against you for exercising your privacy rights.

12. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights:

  • Right to Know: Know what personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion of your personal information (with certain exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale: We do not sell personal information. There is nothing to opt out of.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide our services
  • Non-Discrimination: We will not discriminate against you for exercising any of these rights

To submit a CCPA request, email privacy@givalgo.ai with "CCPA Request" in the subject line. We will verify your identity before processing the request.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Send an email notification to registered users at least 14 days before the change takes effect
  • Post a prominent notice on our website for 30 days following the change

Your continued use of our services after the effective date of any updated policy constitutes your acceptance of the revised terms. If you disagree with the changes, you may close your account and request deletion of your data.

We maintain an archive of previous versions of this Privacy Policy available upon request.