Enterprise architecture · nonprofit control

WordPress is the foundation. CauseWorkHub is the operating system.

CauseWorkHub uses mature, widely supported WordPress infrastructure without behaving like an ordinary public website or a pile of plugins. Each nonprofit receives one isolated private Hub, on its own host, under its own control.

A controlled application environment

Your nonprofit is not a tenant in our shared database.

The organization hosts a dedicated subdomain such as hub.yournonprofit.org. CauseWorkHub runs there as the single application plugin. The nonprofit controls the installation, database, encrypted files, backups, exports and hosting relationship. CauseWork Central does not need a copy of operational data for the Hub to work.

01Your public websiteKeep WordPress, Wix or the site you already use.
02Small connectorPublic forms and Website Chat pass only authorized submissions.
03Private Hub subdomainOne isolated CauseWorkHub application for one legal nonprofit.
04Private databaseOperational records remain inside the organization’s environment.
05Encrypted VaultSensitive file bodies remain outside the public web root.
Not the Media Library

Documents live in a private encrypted Vault—not public WordPress uploads.

CauseWorkHub stores file bodies on the nonprofit’s server outside the public web root. Files receive randomized stored names, authenticated encryption, integrity verification and permission checks on every view or download. They are not inserted into WordPress Media Library and never receive a public attachment URL.

Encrypted before storage

Authenticated streaming encryption protects the file body at rest and detects tampering or truncation.

Need-to-know access

Restricted and Ultra-Restricted documents require named access; an administrator title alone does not silently unlock the content.

Audited delivery

Short-lived application routes authorize downloads and record successful and denied access without copying protected contents into the audit log.

One private application

CauseWorkHub is the only plugin in the Hub.

This is a security boundary, not a limitation. The private installation has no page builder, SEO suite, analytics tracker, advertising code, public form plugin or unrelated utility executing beside sensitive operations. System Health identifies even an inactive extra plugin. Backups, firewalling, monitoring and malware protection stay at the server layer where they belong.

  • Private, no-store application responses
  • Required multi-factor authentication
  • Role-aware application sessions
  • Granular workspace permissions
  • Browser file editor disabled
  • Host-level error display suppressed
Public website stays public

One small connector handles forms and chat.

The CauseWorkHub Chat & Forms Plugin belongs on the nonprofit’s public WordPress website—not inside the private Hub. It connects published forms and Website Chat to the organization’s own Hub through a narrow, deliberate interface. Non-WordPress sites can use the published embed path; Wix exploration is a future distribution conversation, not a dependency for launch.

Familiar infrastructure. Enterprise-grade separation.

WordPress powers an enormous share of the web and is already understood by nonprofit hosts and web professionals. CauseWorkHub uses that availability as leverage while imposing a contained application shell, private storage, strong identity and a single-plugin rule that ordinary WordPress sites do not.

Simple handoff

Your host gets a short checklist—not a scavenger hunt.

Send the hosting requirements page to your hosting company or web professional. It separates ordinary provisioning tasks from the security controls CauseWorkHub enforces itself.

Open the host-ready requirements →

Enterprise capability without enterprise captivity.

See the complete operating system in the live demo, then bring your host or web professional the exact technical checklist.

THE BUILD KEEPS MOVING

Stay close to what CauseWork solves next.

Release news, product commitments, nonprofit research and the path to purchase—sent deliberately, never constantly.