Here we explain exactly how we protect the information you trust us with: where it's stored, who can access it, and what happens if something goes wrong.
Every guarantee below is something technical and concrete, not a marketing promise.
Enforced at the database level (Row-Level Security), not just in application code. Even a programming mistake can't return another church's data.
All communication uses HTTPS. Data is encrypted at rest by our infrastructure providers.
A full copy of the database every day, integrity-checked, retained in tiers: daily, weekly, monthly and yearly.
Access attempts and sensitive events are logged: who, when and from where.
Request size limits, per-user rate limiting, and a maximum execution time on every database query.
Application and database in the same region, in Frankfurt, Germany.
Security answers use language a pastor or treasurer understands, no IT department required.
The guarantees live in the architecture, not in the memory or goodwill of whoever happens to run the system.
This page lists what's real today. If something changes, this page changes with it.
We don't ask you to trust us blindly. We ask you to verify.
This is the philosophy behind every guarantee on this page.
Database managed by Neon, files by Cloudflare, hosting by Render, all SOC 2 Type II certified.
See the full security architecture →No. Isolation happens at the database level with Row-Level Security, not just in the application. Even with a programming mistake, a query can't return another church's data.
In the European Union, in Frankfurt, Germany. The application and database run in the same region.
Every day, with automatic integrity verification before each copy is promoted to weekly, monthly or yearly.
Yes. Your data is yours. You can export it at any time.
No credit card. No commitment.