Protect sensitive records without building an internal security team

Nonprofits may hold donor, staff, volunteer, program, and participant information in the same cloud tenant.

Security Stack

Security should match the information in your care

Not every nonprofit holds the same data or faces the same consequences. The program starts with the accounts, devices, sharing, and recovery needs inside the agreed scope.

  • Identity

    Protect staff and volunteer accounts

    Multi-factor authentication, administrator controls, and sign-in monitoring reduce the reach of stolen credentials. Named accounts make access easier to review and remove when a role ends.

  • Email

    Reduce phishing and impersonation

    Email controls filter common account-takeover, fake-invoice, and impersonation attempts. Suspicious activity follows the agreed response process.

  • Devices

    Protect supported devices in scope

    Managed endpoint protection, encryption, and security updates apply to supported staff devices placed in the program. Personal or partner devices remain outside endpoint coverage unless enrolled.

  • Sharing

    Review access to sensitive folders

    Shared drives, SharePoint sites, guest access, and external links are reviewed around the teams and programs that use them. Access is removed when a staff or volunteer role ends.

  • Recovery

    Back up the cloud tenant independently

    Microsoft 365 or Google Workspace data is backed up outside the tenant and tested for recovery. Donor, case-management, fundraising, grant, and program systems need separate recovery decisions.

  • People

    Make training part of the program

    Short training and safe phishing simulations help staff and volunteers recognize common lures. Awareness training is included for nonprofits without a separate training fee.

Business Value

What the program does for your organization.

The organization gets clearer access, protected cloud accounts and devices, a recovery plan for tenant data, and records that leaders can use in board, funder, or insurance discussions.

01

Protect sensitive access

  • Named staff and volunteer accounts with defined permissions
  • External sharing and stale access reviewed on a schedule
02

Keep the program practical

  • Coverage follows supported users and devices placed in scope
  • Awareness training included without a separate training fee
03

Report clearly

  • Records for access, backup, monitoring, and patching
  • Quarterly reviews that identify gaps, actions, and ownership

What stays yours

The organization remains responsible for privacy, safeguarding, funder, contractual, and records decisions. Teclara operates and documents the security controls in scope. Donor, case-management, fundraising, grant, program, and partner systems are included only when named explicitly, and personal devices are covered only when enrolled.

One managed program that covers the controls below.

Managed Security & Compliance covers the full stack: monitoring, endpoint protection, email security, backup, patching, and platform administration on Microsoft 365 or Google Workspace.

Human-led monitoring
A 24/7 security team detects and responds to threats, not just an automated alert.
Endpoint protection
Managed detection and response on supported staff devices placed in scope.
Email and fraud protection
Controls for phishing, impersonation, and invoice fraud, with suspicious activity reviewed.
Cloud backup and recovery
Microsoft 365 and Google Workspace backed up daily, with tested restores.
Login monitoring
Cloud sign-ins watched for account takeover, with response following an agreed process.
Patching and vulnerability management
Systems patched on a defined schedule, with known weaknesses prioritized by risk.
Security awareness training
Ongoing training and simulated phishing to keep the team sharp.
Tenant configuration
Microsoft 365 or Google Workspace settings reviewed and updated against the security baseline.
See the full service

Platform Expertise

Secure configuration for Microsoft 365 and Google Workspace.

We configure the identity, sharing, email, and retention controls your organization relies on, then keep them under review.

Microsoft 365

4 areas covered

  1. MFA and administrator controls for staff accounts
  2. SharePoint and OneDrive access reviewed by program
  3. Managed endpoint protection on supported devices
  4. Staff and volunteer access removed through offboarding

Google Workspace

4 areas covered

  1. MFA and administrator controls for staff accounts
  2. Shared-drive and external-sharing access reviewed
  3. Gmail phishing and impersonation protection
  4. Staff and volunteer access removed through offboarding

Included

Configuration updates are part of the service. When our security baseline changes, your environment is updated without a separate project fee.

Frequently asked questions.

Can the program fit a smaller nonprofit?

Scope and pricing follow the supported users, devices, and systems placed in the program. We identify the controls that matter for the information and work involved, then make the inclusions and exclusions explicit. Awareness training is included for nonprofits without a separate training fee.

Which nonprofit information can be covered?

The program can protect accounts, email, files, sharing, and supported devices in Microsoft 365 or Google Workspace. Donor, case-management, fundraising, grant, program, and partner systems require separate scoping because they may sit outside the cloud tenant.

Can you secure a nonprofit that runs entirely on Google Workspace?

Yes. Work can include administrator and sign-in controls, Gmail protection, shared-drive permissions, external sharing review, supported devices, independent backup, monitoring, and staff or volunteer offboarding. Available controls depend on Workspace licensing and the systems placed in scope.

Are remote staff and volunteers covered?

Account controls can follow users outside the office. Managed endpoint protection applies only to supported devices that are enrolled, while personal or partner devices remain outside endpoint coverage. The organization decides which roles and devices must meet each access rule.

What evidence can boards or funders receive?

Reporting can include sign-in and access records, backup and restore evidence, patching and vulnerability status, alert response records, and written control descriptions. The organization remains responsible for its board, funder, audit, privacy, and safeguarding conclusions.

What is included, and what requires Managed IT?

Managed Security & Compliance covers the agreed security controls, monitoring, endpoint protection, cloud backup, patching, awareness training, and tenant security configuration. General helpdesk, device procurement, routine user support, and full day-to-day technology administration are included only with Managed IT, which is built on the security program.

Client Feedback

What a client says about working with us.

Wadhah at Teclara is amazing.

M.C.

Chief Executive Officer, Education Non-Profit

Wadhah Hussain, Founder of Teclara

Led by Wadhah Hussain, Teclara's founder

20+ years enterprise IT · Big Four alumnus · Microsoft & Google Cloud specialist

Review the accounts and records in your cloud tenant

We review sign-ins, administrator access, mail flow, device coverage, sharing, and backup in your Microsoft 365 or Google Workspace environment. You receive written findings and priorities, including stale volunteer accounts and external links.