Security & Trust

Enterprise-Grade Security
for Your Church

Your congregation trusts you with their most personal information. SteepleOS is built from the ground up to honor that trust with industry-leading security practices.

How We Protect Your Data

Multiple layers of defense, from encryption to access controls, working together to keep your data safe.

AES-256 Encryption

All sensitive data encrypted at rest using AES-256-GCM, the same standard used by banks and government agencies.

Multi-Factor Authentication

TOTP-based two-factor authentication with backup codes. Mandatory for all admin accounts.

Role-Based Access Control

19 granular roles with 60+ permissions ensure staff only access what they need. Principle of least privilege enforced.

Tenant Data Isolation

Each church’s data is completely isolated. Automatic query-level enforcement prevents any cross-organization data access.

Tamper-Proof Audit Logs

Every action is logged with cryptographic integrity verification. Full audit trail for compliance and accountability.

Brute-Force Protection

Automatic account lockout, rate limiting, and Have I Been Pwned password checking protect against unauthorized access.

Secure Infrastructure

HTTPS enforced, HSTS with preload, Content Security Policy, and comprehensive security headers on every response.

GDPR & Privacy Compliant

Data export, retention policies, and privacy-by-design architecture. Your congregation’s data is handled with care.

Compliance Standards

SteepleOS aligns with recognized industry standards so you can confidently meet your compliance obligations.

SOC 2

SOC 2 Type II Aligned

Controls mapped to SOC 2 trust service criteria for security, availability, and confidentiality.

GDPR

GDPR Compliant

Full data subject rights support including export, deletion, and consent management.

OWASP

OWASP Top 10 Protected

Proactive defense against injection, broken auth, XSS, and all OWASP Top 10 vulnerability categories.

PCI

PCI-DSS Aligned

Payment handling follows PCI-DSS standards. No card data stored on our servers.

NIST

NIST 800-63B

Authentication follows NIST digital identity guidelines for credential strength and lifecycle.

How We Handle Your Data

Transparency is core to our security posture. Here is exactly how your data is stored and protected.

US Data Centers

Data hosted in SOC 2-certified US data centers via Supabase and AWS with automatic backups and failover.

Encryption Everywhere

TLS 1.3 encryption in transit. AES-256-GCM encryption at rest. Keys rotated on a regular schedule.

Regular Security Audits

Automated vulnerability scanning and dependency auditing with rapid response to advisories.

No Data Selling or Sharing

We never sell, share, or monetize your congregation’s data. Your data belongs to your church, period.

Trusted by Churches Nationwide

From small congregations to multi-campus organizations, churches trust SteepleOS to protect their most sensitive data.