Security & Stewardship

Built for the elder board's review.

Tenant isolation at the query layer, role-gated endpoints, encrypted credentials, PCI-aware payments, and confidential pastoral notes that stay confidential. Designed to clear an elder review.

Security posture

Defense in depth, not a marketing badge.

domain

Multi-tenant isolation

Every church is fully isolated. Tenant scoping is enforced at the query layer — not as an application convention. No shared state, ever.

badge

Role-based access control

Built-in roles: Member, Volunteer, Group Leader, Staff, Pastor, Finance, Admin, Executive. Confidential pastoral notes visible only to authorized roles.

credit_card

PCI-aware payments

Online giving runs on a PCI-DSS compliant processor. The platform never touches a card number directly. Tokenized at the form, charged via the gateway.

key

Encrypted credentials

Per-organization API keys (OpenAI, payment processors, integrations) are encrypted at rest. Falls back to server-level configuration if no tenant key is set.

lock

Encryption in transit

HTTPS-only across every surface. HSTS-eligible. Modern TLS, no legacy protocols. Public webhooks are signed and verified.

history

Audit trail

Every mutation — gift recorded, person edited, pastoral note added, role changed — is logged with user, timestamp, and source. Full replay per record.

Pastoral confidentiality

Pastoral notes that stay pastoral.

Senior pastors ask this first. The answer is short: pastoral notes, prayer requests, and care details are role-gated, audit-logged, and excluded from generic AI prompts unless explicitly authorized.

Confidential by default

  • Pastoral notes are visible only to authorized care roles — never to general staff
  • Confidential prayer requests can be marked private or anonymous at submission
  • Sensitive life events (illness, family crisis) are flagged and access-logged

Giving is treated separately

  • Individual gift amounts are restricted to finance roles & the senior pastor
  • Aggregate giving health is visible to executive pastors without exposing individual records
  • Donor information is excluded from AI prompts unless required for a finance task

Member-facing controls

  • Members can view and update their own profile, family, and communication preferences
  • Each member sees only their own giving history & statements
  • Right-to-be-forgotten / data export workflows for jurisdictions that require them

What is logged

  • Every read of a pastoral note — who, when, from where
  • Every export of a giving list — with reason annotation
  • Every role grant or revocation — immutable audit log
AI data handling

How AI uses your data — precisely.

Buyers ask this second. The answer is short: AI calls are scoped, rate-limited, read-only for analytics, and never used to train a third party.

Scoped & org-isolated

  • Every AI call is scoped to the calling user's church — no cross-tenant data exposure
  • The Pastoral Assistant is read-only: it analyzes data, it does not modify it
  • Tenant-supplied OpenAI keys are honored when configured; otherwise platform keys are used

Rate-limited & tracked

  • Per-user rate limits prevent runaway cost or abuse
  • Every AI call is logged with user, model, token usage, and outcome for audit
  • Cost-optimized models for high-volume paths; flagship models for the assistant & comms drafting

What is sent to the model

  • Only the prompt context required for the task — not your entire database
  • Pastoral notes & confidential prayer requests are excluded from generic prompts
  • Donor PII is excluded from comms-drafting prompts unless personalization is explicitly requested

What is not

  • Your data is not used to train third-party models (per OpenAI API terms for paid plans)
  • The platform does not share church data across organizations — not for AI, not for benchmarking
  • You can disable AI features per-tenant if your elder board requires it
Stewardship & procurement

What elder boards and admins need.

description

Documentation for review

  • Security questionnaire responses (SIG-lite, CAIQ format)
  • Data Processing Addendum (DPA) on request
  • Standard MSA & SaaS subscription terms
  • Reference architecture & data-flow diagrams
  • Insurance certificates on request
handshake

Deployment & onboarding

  • Cloud-hosted SaaS — no servers to provision
  • Per-tenant subdomain or custom domain
  • Standard onboarding: campuses, ministries, people import in 2–4 weeks
  • You can start with one ministry and expand
  • CSV import for existing people, giving history, and pledge data
payments

Church-friendly licensing

  • Per-church pricing — no per-seat surprises
  • Annual or monthly billing
  • Discounted tiers for church plants and small congregations
  • No-cost pilot programs for qualifying churches
contact_support

Support & SLA

  • Direct line to engineering — no Tier 1 maze
  • Standard 99.9% uptime target
  • Status page for incidents & planned maintenance
  • Documented backup & restore procedures
Standards we align to

Familiar frameworks for IT review.

SanctuaryIQ aligns its controls to recognized security frameworks and payment-industry standards. Formal certifications are added as the customer base requires.

verified NIST CSF aligned
verified OWASP ASVS practices
verified PCI-DSS via processor
verified SOC 2 roadmap

Need our review packet?

Send us your elder board's questions and we'll respond with the security questionnaire, DPA, and reference architecture you need.

Request the packet arrow_forward