Security and Privacy Posture
ArtMetrics treats public-record aggregation, user submissions, and reviewer access as trust-sensitive systems that require clear controls and data boundaries.
Public-record data
IRS 990 filings, state charity registrations, and other public-record data are aggregated from publicly available sources and are not treated as confidential. This data is displayed as part of the source filings it was drawn from.
Account and request-access data
Account information, request-access submissions, and correction requests are kept separate from the public-record dataset. ArtMetrics collects only the information needed to evaluate the request — name, organization, contact details, and the specific record in question.
Access controls
- Restricted areas use role-based access gates for authenticated reviewer and admin activity.
- Sensitive actions (approvals, corrections, admin views) require an authenticated session; public pages do not require login.
- Access to raw compensation and person-level data beyond public summaries is limited to approved reviewer accounts.
Logging
Authenticated activity — including login, correction submissions, and reviewer approvals — is logged for audit and abuse-prevention purposes. Logs are used to investigate account issues and correction disputes, not for behavioral tracking.
Data retention
Public-record data is retained indefinitely as part of the historical filing archive. Account and correction-request data is retained only as long as needed to support the account, the correction record, or applicable legal and audit requirements.
Security contact
Report a security or privacy concern to privacy@artmetrics.co. Include enough detail for the team to reproduce or verify the issue.