Know every supporter. Catch every lapse. Flag every fraud.
Cause Shield threads every donation, event registration, peer-to-peer fundraiser, and site visit into one supporter view, then scores who's about to lapse, flags every suspicious transaction, and emails the right person every morning. Donor intelligence, fraud, and uptime: one tool, one inbox.
From $34/month · cancel any time · donor PII minimised by default
- DONATION$150 monthly · Sarah C.2m ago
- FRAUD FLAGCard-testing pattern · 3 attempts blocked4m ago
- DIGESTDaily summary sent · Eddie + 2 others9m ago
Works with the platforms you already run on
- Funraisin
- Raisely
- Stripe
- Classy
- GiveWP
- Donorbox
The reality of running a donation site in 2026
Six problems that quietly bleed nonprofits, and six layers of defence in one tool.
You don't actually know who your supporters are.
Sarah donated $50 last year, registered for the 10km run in March, set up a peer fundraising page that's raised $1,240, and visited the campaign page this week. Today you'd need three tools and twenty minutes to find that out. With Trails it's one page.
Recurring donors lapse silently.
A card expires, a charge fails, a gift drops from $50 to $25, and your team doesn't know until renewal income mysteriously drops. Supporter Pulse scores every recurring donor weekly and flags the ones worth a personal call.
Fraud is rising on donation forms.
Card-testers love charities. Small amounts, fewer fraud teams, recurring giving for cover. By the time chargebacks arrive, the cards are already burned.
Your donation page might be inaccessible, and you might not know it.
Missing alt text, illegible contrast, unlabelled form fields. A supporter using a screen reader hits these walls every day. Cause Shield runs an automated WCAG 2.2 AA scan every month and tells you what to fix in plain English.
Your platform's uptime isn't your uptime.
When your fundraising platform has a hiccup, donors see a broken page. You usually find out from a board member, not a status page.
Sometimes the alarming thing is silence.
Your donation form looks fine. Stripe says 'all systems green'. But for the last 90 minutes nobody has donated and it's a Thursday at 2pm. That's a problem you'd want to know about before the campaign team does. Absence alerts watch for the silence.
What you get
Seventeen purpose-built features. One integration. One inbox.
Supporter Trails
Every donor, event registrant, peer-to-peer fundraiser, ticket buyer, and site visit threaded into one timeline per supporter. AI-written stories tell you who someone is in 15 seconds.
Atlas: cohort discovery
Trails for groups. Atlas surveys your supporter base every day across nine dimensions (recurring status, lifetime giving, channel mix, recency, age band, state, country, plus any demographic field your fundraising platform sends), with week-over-week deltas and plain-English narratives on each. The biggest mover lands in your daily digest.
Smart condition alerts
Type your alert in plain English ("ping me when an anonymous donation lands over $5,000") and we compile it once against a real payload sample. Subsequent events evaluate deterministically with zero AI tokens. Available on every plan.
Supporter Pulse
Churn-risk scoring on every recurring donor. Card decline, retry count, expiry, gift-size drift. Save one lapsing $25/mo gift a year and Cause Shield pays for itself.
Real-time fraud flagging
Every donation scored in under 200ms using behavioural signals tuned for nonprofit traffic.
AI digest emails
Daily fraud summary, weekly traffic narrative, monthly security report, all written in plain English by Claude. Send time and timezone are yours.
Uptime monitoring
Multi-region checks on your donation form, every minute. Email the right teammate the moment it goes red.
Absence alerts
Fire an alert when activity you expect doesn’t happen. "Tell me if I don’t see at least one registration in 15 minutes between 9–5 weekdays." Catches broken donation forms, payment-gateway hiccups, and quiet campaigns before they cost a day of giving.
AI traffic analytics
See where your donors come from. No tagging, no tracking plan. Channels, devices, goals, week-over-week deltas.
Smart webhook classifier
One URL for every event your platform sends. AI detects donations, registrations, refunds, and spam. No tagging.
Third-party Stripe Connect
Run campaigns where the Stripe account belongs to a charity? Send a magic-link invite. They authorise without a Cause Shield account; you stay in the dashboard.
Monthly security scan
A defensive external audit every month: TLS, security headers, DNS hygiene, exposed paths. Written in plain English. Not annual. Not optional.
Monthly accessibility scan
An automated WCAG 2.2 AA scan every month: missing alt text, contrast, form labels, heading order, ARIA misuse. Detected issues come with plain-English fixes prioritized by impact on supporters. Catches the structural ~30–40% of WCAG; a manual audit by a certified professional is still the gold standard.
Team-aware alerts
Finance, IT, and ED each see what they need. Role-based access and per-site scoping on every plan.
Public status + share links
A status page donors can subscribe to, and read-only dashboard shares for boards and auditors. No login required.
Pick your data region
Australia (Sydney), Europe (Ireland), or United States (Virginia). You choose at sign-up, we pre-select from your network location. Donor data lives entirely in your region. GDPR-aligned for EU + UK customers; Privacy Act-aligned for Australian charities.
Audit log
Every action (invites, role changes, share links, plan upgrades) recorded and exportable. Your compliance team will thank you.
Why monitoring matters
$16.6B
lost to cybercrime in the US in 2024, a 33% jump in a single year.
FBI IC3 2024 Annual Report
1 / 6 min
cybercrime reports filed in Australia. 87,400+ in the last fiscal year.
ASD Annual Cyber Threat Report 2023–24
$76k
median loss per occupational fraud case at nonprofit organisations.
ACFE Report to the Nations 2024
Statistics from publicly published industry reports. Verifiable links available on request. We won’t cite numbers we can’t back up.
How it works
Up and running in fifteen minutes.
- 01
Connect your Stripe
Read-only OAuth. We start scoring every donation for fraud in real time. No code changes.
- 02
Drop in the script
One async tag in your donation page's <head>. Tracking + uptime go live immediately.
- 03
Point your webhooks
Send platform events to one URL. AI figures out what's a donation, what's a registration, what's spam.
What it looks like
One supporter, one timeline. One dashboard, three emails. Everything else falls into place.
Sarah C.
s***@gmail.com
Story · AI written
Sarah's monthly $50 gift has been running smoothly for 11 months. She registered for City2Surf 10km last week and set up a fundraising page that's raised $1,240. Her card on file expires next month, so it's worth a personal note.
Donated A$50 monthly recurring · card on file
Registered City2Surf 10km · solo entry
P2P page "Run for Mum" · A$1,240 raised · 18 donors
Visited /campaigns/end-of-year-appeal · Facebook
Supporter Trails
Every donor, every event, every page view, threaded into one timeline.
Donations, registrations, peer-to-peer pages, and site visits stitched into a single per-supporter view. AI-written story at the top tells you who someone is before you pick up the phone. Pulse score flags who's about to lapse.
Security report: May 2026
3 findings · 1 medium fixed · TLS still A+
Weekly traffic summary for donate.example.org
Visitors ↑ 18% · 2 new goals firing · email is your top channel
📊 Daily fraud digest, May 10
12 flags · 2 critical · card-testing wave on donate.org
Digests
Three emails. Zero dashboards opened.
Daily fraud summary, weekly at-risk supporters, monthly board report. Send time and timezone are yours.
Live dashboard
Everything that needs you, at a glance.
Fraud flags, at-risk supporters, uptime, traffic vitals. Refreshed every page load.
Smart webhook classifier
One URL. Every event categorised.
Donations, registrations, refunds, disputes, spam: all sorted, all in plain English.
Goal · First donation
68% of weekly target
Goal tracking
Conversions without a tagging plan.
Mark URLs or events as goals. Cause Shield watches them and tells you when something moves.
Board-shareable share links
Read-only, no login required.
A signed URL your treasurer or auditor can open from a coffee shop. Revocable, scoped, audited.
Sarah C.
A$50 / mo · 11mo run
Card expires in 14 days
James K.
A$25 / mo · 4y run
Healthy
Aisha M.
A$100 / mo · 6mo run
Last gift down 50%
Supporter Pulse
Catch the lapse before it happens.
Every recurring donor scored weekly using card decline, retry count, expiry, and gift-size drift. Surface the at-risk ones in time to call.
Uptime monitoring
Multi-region checks, every minute.
When your donation page goes red, you hear before donors do. AU, US, EU vantage points; alerts route by site to the right teammate.
Active recurring donors
Up 2% week-over-week. Avg gift A$42 / mo.
NSW supporters
11% recurring rate. Largest state cohort by some margin.
Lapsing (30–90 days)
Growing fast. 90% are first-time donors.
Atlas
Your supporter base, mapped each week.
Cohort discovery for grown-up data sets. Atlas surveys your supporters every day across nine dimensions (recurring status, gift bands, channel mix, recency, age, state, country, and any demographic field your platform sends), with week-over-week deltas and plain-English narratives.
Your rule
“ping me when an anonymous donation lands over $5,000”
Deterministic rule
is_anonymous = true
AND amount > 500000
Smart condition alerts
Type the rule. We compile it once.
Natural language in, deterministic evaluator out. Every later event evaluates in microseconds with zero AI cost, and you see the compile, so you can audit what we built.
Charity Australia
awaitingSent to finance@charity.org · 14d
Riverside Foundation
activeacct_1Nz9aP… · webhook registered
Third-party Stripe Connect
Invite a charity to connect, no account needed.
Run campaigns where the Stripe account belongs to someone else? Send a magic-link invite; the owner authorises in one click and gets a permanent disconnect link by email. No Cause Shield seat consumed.
From the team
We built Cause Shield because the charities we've spent our careers building tools for deserve the same safety net banks take for granted.
The Cause Shield team. Years inside donation platforms, built specifically for how charities actually run.
Pricing
Three tiers. No annual contracts. No setup fees.
Starter
- ✓1 website · 1 Stripe acct · 1 user
- ✓Real-time fraud flagging
- ✓Daily fraud digest
- ✓Pick your data region: AU, EU, or US
Growth
- ✓3 websites · 3 Stripe accts · 3 users
- ✓Absence alerts that fire when expected events don't arrive
- ✓Slack + Teams delivery
- ✓Uptime monitoring with custom audience
Partner
- ✓Unlimited everything
- ✓Monthly security report
- ✓AI traffic analytics
- ✓Smart webhook classifier
Frequently asked questions
The questions finance and IT leads actually ask.
Do you store donor PII?+
Minimal by default. Donor names and emails flowing through our smart-webhook receiver are SHA-256 hashed with a per-organisation pepper before they touch the database. We never persist the raw payload from your fundraising platform. Stripe shares the donor email on each charge so you can review flagged donations; we store that email so we can show it to you, and never share it beyond the sub-processors disclosed in our DPA. When you enable Supporter Trails (Partner), those data points are threaded into one per-supporter view, and you can switch your organisation into "masked" mode at any time to mask emails in the UI and disable AI-generated supporter summaries. We do not collect phone numbers, addresses, dates of birth, or card data.
Is this PCI compliant?+
Cause Shield never sees raw card data, so PCI DSS scope doesn't extend to us. Your payment processor remains the system of record. We do follow PCI-aligned operational practices: encrypted-at-rest storage, scoped access controls, and the monthly security scan covers our own infrastructure too. We don't hold a SOC 2 attestation yet and won't claim one until we do.
How is this different from Stripe Radar?+
Radar only sees what Stripe processes, scored against Stripe's general e-commerce model. Cause Shield watches your entire donation funnel (including Funraisin / Raisely platform events, uptime, and traffic) and is tuned for nonprofit patterns where giving days, recurring gifts, and tribute donations look nothing like normal e-commerce. Most customers run both; we catch the gaps.
Will the tracking script slow my donation page?+
The script is roughly 3KB gzipped, loaded async with no render-blocking, and beacons events via sendBeacon so it never holds up navigation. We honour navigator.doNotTrack and add a per-page opt-out attribute. If you measure a regression, let us know. We're not interested in being the reason your donation form converts worse.
What happens if Cause Shield goes down?+
Our fraud scoring fails open by default: if we can't return a verdict in time, the donation proceeds and we log the miss. Your donation form never breaks because of us. Uptime checks run independently of the dashboard, so a Cause Shield outage doesn't blind your alerting either.
What does the monthly security scan actually check?+
It's automated and defensive. We check TLS configuration, HTTP security headers, DNS hygiene (SPF, DKIM, DMARC, DNSSEC, CAA), exposed sensitive paths against a curated wordlist, and common misconfigurations, then Cause Shield's AI writes the report in plain English. We deliberately do NOT run active exploitation, port scans, fuzzing, brute-force, or authenticated tests; this is a configuration audit, not a penetration test. Treat it as continuous external posture monitoring and complement it with an annual manual penetration test by a human security engineer for regulated or high-stakes work.
Do you work with my donation platform?+
We're built around Funraisin and Raisely first, but the smart webhook classifier handles arbitrary JSON, so most platforms work out of the box. If yours has an unusual payload shape, send a sample and we'll add explicit support, typically within a week, free.
Can we cancel any time?+
Yes. Monthly billing, no annual lock-in, no setup fees. Cancel from your dashboard and you keep access through the end of the current billing period. We export your historical data as JSON or CSV on request, no charge.
Ship safer fundraising infrastructure this week.
From $34 a month. No setup fees. Real fraud monitoring in fifteen minutes.