Skip to main content

How AnyGrant handles your data

What is stored, who can see it, and how the public data on the site is sourced.

Each workspace is separate

Every record belongs to one workspace. Each request is checked on the server: your session, your permission, your membership of the workspace and your role, before anything is read or written. The workspace comes from your session, never from the page, so a page cannot ask for another organization’s data.

Roles

Invite people by email and give each the role they need. Invitations expire after 14 days.

Owner
Everything an editor can do, plus inviting people and connecting or disconnecting integrations. A workspace always keeps at least one owner.
Editor
Works on grants, budgets, spending and reports.
Viewer
Reads everything and changes nothing.

Integration credentials

When you connect an integration, its tokens are sealed with AES-256-GCM before they are stored, bound to your workspace so a sealed value cannot be opened in another one.

Uploads

A file’s extension and its contents must both match an allowed type, and every file is scanned for malware before it is stored. If the scanner cannot be reached the upload is refused, so an unscanned file is never kept. Downloads go only to members of the workspace, through links that expire after five minutes.

Where data is stored

Workspace data is kept in AnyGrant’s own database and files on its own server, not in a third-party file service. The database accepts connections only from the server itself.

Public data is cited

Opportunities, funders and returns come from public sources, and every figure links to the listing, page or return it came from, so you can check it yourself. See the sources.

Free while AnyGrant is in beta

Every feature, for your whole team. What it costs after the beta.

All Rights Reserved. ©️ 2026 Telesto Innovations, LLC

BUILT IN DENVER