Donor records. Grant proposals. Client case files. Your non-profit handles some of the most sensitive data in any sector, and when staff use AI tools for grant writing, donor management, or client services, that data can leave your control in a single paste.
Shield keeps everything on your machines. No donor PII ever reaches ChatGPT, Claude, or Copilot.
Shield keeps donor records, grant proposals, client case files, and payment data from ever reaching external AI providers. It installs on your staff's Mac, Windows, or Linux machines and redacts sensitive information, names, addresses, EINs, health data, credit card numbers, and donor gift details, before prompts leave your organization's network. Because redaction happens locally, no donor PII, client PHI, or financial data ever touches ChatGPT, Claude, Copilot, or any cloud AI service.
See What Shield Redacts
Select a scenario to see how Shield redacts sensitive non-profit data before it reaches external AI providers. The left panel shows what your staff might paste into an AI tool. The right panel shows what actually leaves your machine after Shield processes it.
Development Director Drafting a Federal Grant Proposal with AI
A non-profit development director uses an AI assistant to draft a federal grant proposal, pasting program budget details, client impact data, organizational financials, and partner contact information into the prompt.
Before Shield, Raw Prompt
Draft the needs assessment section for our SAMHSA grant proposal. Our organization, HopeBridge Community Health (EIN 94-2288441), serves 3,400 uninsured patients annually across 7 clinics in rural Oregon. Executive Director: Dr. Maria Fernandez, LCSW, {{REDACTED_PII_EMAIL_007}}, {{REDACTED_PII_PHONE_003}}. Program budget: $2.4M total ($1.8M federal request, $600K match from The Whitfield Foundation). Key personnel: Clinical Director James Okonkwo, PhD (salary $118,000), Lead Case Manager Sarah Chen, MSW ($72,500). Impact data: 89% of clients showed improved PHQ-9 scores within 12 weeks. Community partner letters attached from Mercy Hospital (contact: Robert Tanaka, {{REDACTED_PII_EMAIL_008}}) and Benton County Health Department (grant #OR-BCH-2026-441).
After Shield, Safe Output
Draft the needs assessment section for our [AGENCY] grant proposal. Our organization, [ORGANIZATION_NAME] (EIN [TAX_ID]), serves [PATIENT_COUNT] uninsured patients annually across [CLINIC_COUNT] clinics in [REGION]. Executive Director: [DIRECTOR_NAME], [CREDENTIALS], [EMAIL], [PHONE]. Program budget: [BUDGET_TOTAL] total ([FEDERAL_REQUEST] federal request, [MATCH_AMOUNT] match from [FOUNDATION_NAME]). Key personnel: Clinical Director [NAME], [DEGREE] (salary [SALARY]), Lead Case Manager [NAME], [DEGREE] (salary [SALARY]). Impact data: [PERCENTAGE] of clients showed improved [METRIC] scores within [TIMEFRAME]. Community partner letters attached from [HOSPITAL] (contact: [NAME], [EMAIL]) and [DEPARTMENT] (grant #[GRANT_NUMBER]).
Shield Caught (8 matches)
PII, Org IDEIN / Tax ID
PII, NameExecutive Director
PII, EmailStaff Email
PII, PhoneStaff Phone
Sensitive, FinancialBudget Figures
PII, NameStaff Names + Salaries
PII, Name / EmailPartner Contact Info
Sensitive, GrantPartner Grant Number
Why Non-Profits Need AI-Specific Data Protection
Donor Trust
The currency of every non-profit
A single data exposure involving donor names, gift amounts, or personal circumstances can destroy relationships built over decades. Donors who give major gifts expect absolute confidentiality, and when their personal data appears in an AI provider's logs because a staff member pasted it into ChatGPT for a cultivation strategy, that trust is broken. The risk is not just financial, it's existential. Unlike for-profit companies, non-profits cannot rebuild trust through discounts or service credits. Donor trust is the entire business model.
Based on industry fundraising best practices and IRS donor privacy protections under IRC §6104
Multi-Framework
Non-profits face overlapping regulatory obligations
A single non-profit health clinic may be subject to HIPAA (for patient data), PCI DSS (for credit card donations), GDPR (for international donors), state charitable solicitation laws (in 39+ states), IRS 990 Schedule B privacy requirements, and state data breach notification laws (all 50 states). AI tool usage creates a new vector that touches every framework simultaneously because staff paste data from every domain into the same AI prompt. Shield provides one consistent redaction layer that addresses all frameworks at once.
Multiple statutes, HIPAA, PCI DSS, GDPR, IRC §6104, state charitable solicitation laws, state breach notification laws
Local-First
Client data never leaves your organization's machines
Many non-profits cannot use cloud-based security tools because their funders prohibit storing client data on third-party servers (especially federal grants with data sovereignty clauses). Shield runs locally on each staff member's computer, no cloud processing, no vendor data access, no data leaving your organization's control. The redaction mapping stays on the local machine, inside your network boundary. This is essential for non-profits that handle domestic violence survivor data, immigrant legal services, HIV/AIDS patient information, and child protection cases.
Shield operates entirely within your organization's network boundary
How Shield Maps to Your Compliance Frameworks
IRS Form 990 / Schedule B
Scope: Donor names, addresses, and contribution amounts from the largest contributors
Requirement
Schedule B donor identities are exempt from public disclosure under IRC §6104. Organizations must protect this information internally and not voluntarily disclose it through other channels, including AI tools.
How Shield Helps
Redacts donor names, addresses, gift amounts, and DAF account numbers from prompts before they reach external AI providers. Because the data is redacted locally, there is no voluntary disclosure, the AI never receives donor-identifying information.
HIPAA
Scope: Protected Health Information (PHI), applies to non-profit covered entities and business associates
Requirement
Privacy Rule: safeguard PHI from impermissible uses and disclosures. Breach Notification Rule: notify affected individuals, HHS, and potentially media within 60 days of discovering a breach of unsecured PHI.
How Shield Helps
Redacts 18 HIPAA PHI identifiers, including names, dates (beyond year), phone numbers, medical record numbers, and health plan beneficiary numbers, before prompts leave the local machine. The external AI provider never receives PHI, preventing a HIPAA breach notification event.
Protect stored cardholder data (Req 3); encrypt transmission across open, public networks (Req 4); restrict access to cardholder data by business need-to-know (Req 7).
How Shield Helps
Redacts Primary Account Numbers, cardholder names, and payment data before prompts leave the non-profit's cardholder data environment. The AI provider never sees payment card information, satisfying transmission protection requirements for the AI usage vector.
GDPR
Scope: Personal data of EU/EEA residents, donor names, contact information, gift amounts, communication preferences
Requirement
Lawful basis for processing; data minimization; purpose limitation; cross-border transfer safeguards; 72-hour breach notification.
How Shield Helps
Prevents cross-border data transfers of EU resident personal data by redacting it before it leaves the local machine. No data reaches external AI servers, so there is no GDPR-regulated international transfer and no processing by a third party to account for.
CCPA / CPRA
Scope: California residents, personal information collected by non-profits (donor and beneficiary data)
Requirement
Right to know what personal information is collected and shared; right to delete; right to opt-out of sale/sharing; data minimization under CPRA. While non-profits have partial exemptions, donors and beneficiaries retain core privacy rights.
How Shield Helps
Prevents unauthorized sharing of California resident data with AI providers. Because Shield redacts PII before it leaves the non-profit's systems, the data is never shared or sold to a third party, satisfying opt-out and data minimization requirements for the AI use case.
State Charitable Solicitation Laws
Scope: 39+ states require non-profits to register before soliciting donations, many require disclosure of data handling practices
Requirement
Registration filings, annual financial reports, and in many states, disclosure of how donor data is collected, stored, and shared. A data exposure through AI tool use may constitute a violation of state charitable trust laws.
How Shield Helps
Shield's local redaction architecture means donor data never leaves the non-profit's control, supporting the data handling representations made in state registration filings and reducing the risk of regulatory action from state attorneys general.
SOC 2
Scope: Non-profits that receive software grants (e.g., Google for Nonprofits, Microsoft Nonprofit, Salesforce.org) or enterprise partnerships
Requirement
Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria, increasingly required by tech company grant agreements and corporate partnership contracts that involve data sharing.
How Shield Helps
Provides a documented technical control for the Confidentiality and Privacy criteria: redaction of sensitive data before it can be transmitted to unauthorized external systems. This satisfies auditor requirements for data protection controls when staff use AI tools.
How Shield Protects Your Non-Profit's Data
Frequently Asked Questions
Grant proposals are among the most data-dense documents in a non-profit. A typical federal grant application contains your organization's EIN, executive director's name and contact information, program budgets with salary details for key personnel, client outcome data (which may be individually identifiable for small sample sizes), partner organization contact information, and often sensitive community needs data. When your development team pastes this into ChatGPT, Claude, or Copilot for drafting assistance, all of that data leaves your organization's control. Shield redacts EINs, staff names, emails, phone numbers, salary figures, partner grant numbers, and client-identifying data before it reaches any external AI provider.
Yes. IRS Form 990 Schedule B lists your largest contributors, and while donor names and addresses on Schedule B are specifically exempt from public disclosure under IRC §6104, that protection only applies to IRS filings. When your development team pastes major donor records into an AI tool for wealth screening, cultivation strategy, or prospect research, that data goes to an external AI provider with no equivalent legal protection. Donor names, addresses, gift amounts, DAF account numbers, real estate valuations, family medical context (including children's health information), and cultivation strategies all leave your control. Shield redacts donor identities, contact information, financial figures, and sensitive family details before they reach external AI systems, because donor trust, once broken, cannot be restored.
Yes. Many non-profits are HIPAA covered entities or business associates, community health centers, behavioral health organizations, HIV/AIDS service organizations, and any non-profit that transmits health information electronically for treatment, payment, or operations. When your case workers, clinicians, or program staff use AI tools for intake documentation, case notes, treatment planning, or grant reporting that references client health data, that PHI is transmitted to an external AI provider in clear text. Shield redacts PHI identifiers, names, dates (beyond year), phone numbers, medical record numbers, health plan beneficiary numbers, and full-face photos, before they leave your machine. Because the redaction happens locally before transmission, the external AI provider never receives PHI, and you avoid a HIPAA breach notification scenario.
If your non-profit processes credit card donations through a compliant payment gateway, you're already handling cardholder data securely. The gap is when development or finance staff copy-paste donor credit card information, bank account numbers, or ACH routing details into AI tools for reconciliation, reporting, or analysis. PCI DSS Requirement 3 says cardholder data must be rendered unreadable anywhere it is stored, and sending it to an AI provider means it's stored on their servers, outside your CDE. Shield redacts Primary Account Numbers, cardholder names, and payment amounts before they leave your network boundary, keeping your PCI DSS compliance posture intact for this vector.
International NGOs and non-profits with donors in the EU/EEA or UK have GDPR obligations regardless of where the organization is headquartered. When a European donor's personal data, name, address, gift amount, communication preferences, is pasted into an AI tool, that constitutes a cross-border data transfer to the AI provider's servers (often in the US). Under GDPR, you need a lawful basis for that transfer, and 'we use AI to write thank-you letters' is unlikely to satisfy a supervisory authority. Shield prevents the transfer entirely by redacting personal data before it leaves your machine, the data never reaches external servers, so there's no GDPR-regulated processing or transfer to account for.
Yes. Shield installs on any Mac, Windows, or Linux workstation, whether at headquarters, a field office in a different state, or a case worker's laptop in a rural community. For federated non-profits with independently incorporated chapters (e.g., United Way, Boys & Girls Clubs, Planned Parenthood affiliates), each chapter can deploy Shield independently with its own configuration, or your national office can distribute it via MDM with chapter-specific filter rules. All redaction happens locally on each machine, no central server, no cloud dependency, no data aggregation risk. Audit logs can be centrally collected if your compliance team needs visibility.
Your donors, clients, and grant partners trust you with their most sensitive information. Shield makes sure that trust never leaves your organization's control, even when your staff use AI to work faster and serve better.