Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Operations whitepaper | Non Profit Organizations

Choosing and Securing a Donor CRM

Pick the right fundraising database and configure it to protect donor trust

  • Published September 25, 2026
  • 4 min read

Your donor CRM holds the relationships that keep your nonprofit funded. It tracks gifts, pledges, communication history, and often personal notes about major donors. Both the choice of system and its setup matter, because a poor fit or a weak configuration can cost you data and trust.

This guide covers both parts: picking a system that fits how your team works, and configuring it so donor information stays protected.

Define donor CRM requirements before demos

Demos make every system look easy. So write down what you actually need before you talk to vendors.

Start with daily tasks. For example, list how you enter gifts, send acknowledgments, manage recurring donors, and track grants. Next, add reporting needs for the board and auditors.

Finally, note which systems the new platform must connect with, such as your payment processor, email marketing tool, event platform, and accounting software. Also involve the people who will use it every day, because a development associate often spots gaps that a director misses.

Ask vendors hard security questions

A cloud platform shifts some security work to the vendor, but you still own the risk to your donors. Therefore, ask each finalist the same questions and compare the answers.

  • Does the system support MFA and single sign-on with Microsoft 365 or Google?
  • Can you set role-based permissions down to specific fields or records?
  • Does the vendor provide an independent security report, such as a SOC 2 report?
  • How does the vendor encrypt data in transit and at rest?
  • What backups does the vendor keep, and how would you restore deleted records?
  • Does the system keep an audit log of logins, exports, and changes?
  • Can you export all your data in a usable format if you leave?
  • How will the vendor notify you of a security incident?

Then ask for references from organizations similar in size and mission. Also, ask how the vendor handles support requests and outages.

Clean your data before migration

Moving to a new donor CRM gives you the best chance to fix old data problems. Duplicate records, outdated addresses, and inconsistent codes all slow staff down.

First, merge duplicates and standardize gift and campaign codes. Then decide how much history to move. Also, delete data you no longer need, such as old card details or sensitive notes with no business purpose, because less data means less exposure.

In addition, test the migration with a sample before moving everything. Check that gift totals, donor counts, and recurring gift schedules match the old system.

Set permissions by role

Not everyone needs to see everything. For instance, event volunteers may need to check in guests but not view giving history. Similarly, a gift processor may need to enter donations but not export the full database.

Build roles around job tasks, and review membership every quarter. In addition, limit export rights to a few trusted people. Bulk exports to spreadsheets often end up in personal email or on unmanaged laptops.

Also, avoid shared logins. Each person needs a named account, so the audit log shows who did what.

Secure integrations and connected apps

Modern fundraising platforms connect to many other tools. Each connection uses an account or token that can reach donor data.

So keep an inventory of integrations, and remove any you no longer use. Also, tie integrations to a dedicated service account instead of a staff member’s login. That way, connections do not break, or stay open, when someone leaves.

Finally, review what each connected app can read or change. Many integrations ask for broad access by default, even when they need only a small part of the data.

Plan for staff changes and daily hygiene

Development teams often see turnover, and each departure leaves an account behind. Therefore, remove access on a person’s last day, and transfer their saved reports and lists.

Meanwhile, review login and export logs each month for unusual activity. A sudden large export late at night deserves a quick question.

Also, keep a written list of who owns each role and report, so nothing gets lost when people move on.

How WEBIT helps

WEBIT helps nonprofits evaluate donor CRM options against security and integration needs, then plan a clean migration. We can connect the platform to Microsoft 365 single sign-on and roll out MFA, so every login gets stronger protection.

We also protect the devices staff use to reach donor data with Security Essentials. Learn more about our strategic IT services or our workflow automation options for gift processing.

Key takeaways

  • Write down real daily tasks and integrations before you watch demos.
  • Ask every vendor the same security questions, including MFA, audit logs, and data export.
  • Clean and trim data during migration to reduce exposure.
  • Role-based permissions and limited export rights protect a donor CRM from misuse.
  • Service accounts and prompt offboarding keep integrations and logins under control.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Non Profit Organizations IT services

See how WEBIT supports non profit organizations organizations across Chicagoland.

Explore Non Profit Organizations IT →

More Non Profit Organizations whitepapers

Browse the full library of guides for your industry.

All Non Profit Organizations whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.