Welcome

Data Security Policy Summary

100 Basins App Data Security Policy Summary

The Water Resilience Coalition (WRC), as part of the Pacific Institute (PI), has developed the Basins Hub for companies, implementers, and other NGOs to use to collect and share information on various initiatives, including the 100 Priority Basins, collective action, and Positive Water Impact (PWI) to advance corporate water stewardship activities globally.

Recognizing that some data collected can be considered sensitive or confidential, the Basin Hub has been developed following the United States information security framework NIST SP 800-71. This includes ensuring data is securely stored and encrypted at all times, only approved users have access to the application and data, role-based accounts are used to ensure users have access to only the data they need, and the application is hosted in a SOC II audited and compliant cloud environment.

Other security features integrated include multi-factor user authentication, robust password management requirements, and implementation of many best practice security measures for development of secure web applications.

With the exception of name and email address, there is no other personally identifiable information (PII) present in the application and company data is not shared with any 3rd parties without written approval. Companies must submit the names of any 3rd party validators, consultants, or other organizations they wish to access their PWI data and access is time-bound, expiring automatically at the end of the designated review period.

This document is intended to provide a high-level summary of the data security posture of this application. For a full written copy of the Data Security Policy, please email contact@wateractionhub.org or reach out to any CEO Water Mandate staff member.

Last updated: July 22, 2026.