Security & Privacy

Parish data requires careful stewardship.

withDomine is built so parish teams can work with sensitive formation records without giving up ownership or control. Here is how we protect access, limit use, preserve accountability, and respond when something goes wrong.

Last reviewed August 24, 2026Current product and contract practices

Owned by your parish

Parish data remains the property of the parish.

Not sold

We do not sell parish data or use it for advertising.

Encrypted

Production data is encrypted in transit and at rest.

Portable

A complete, machine-readable export is available by request.

Our commitments

The parish stays in control.

Our customer agreement turns the core privacy promises into specific obligations, not just marketing language.

Ownership and limited use

  • All parish data remains parish property.
  • Parish data is not sold or shared for advertising.
  • Use is limited to providing, securing, supporting, maintaining, and operating the service.

Confidentiality and portability

  • Confidential information is protected with at least reasonable care and used only for the relationship.
  • A complete, commonly used machine-readable export is available on request or termination.
  • Deletion and backup-retention timelines are written into the customer agreement.

withDomine is responsible for

  • Protecting the service and parish data
  • Limiting service-provider use
  • Export, deletion, and incident response

The parish is responsible for

  • Choosing who receives access
  • Removing access when roles change
  • Obtaining required participant and guardian consent

Access and identity

Access is deliberate, not assumed.

A person must be authenticated, belong in the current parish context, and be authorized for the requested action. Each layer is checked on the server.

Parish boundaries

Parish-owned records are tenant-scoped on the server. Requests resolve the active parish before protected data is read or changed, and cross-parish access is denied.

Role and capability checks

Directors, staff, volunteers, sponsors, and participants do not receive the same access. Server-side policies and explicit grants can limit access by ministry, program, cohort, assignment, and capability.

Hardened sign-in

withDomine supports password, short-lived magic link, Google, and Microsoft sign-in. Login attempts are rate-limited, repeated failures lock accounts, and inactive sessions expire.

Reviewable sensitive access

Sensitive document previews and downloads pass through authorized application routes and create an access record. Important changes preserve actor, parish, time, and request context.

Current sign-in safeguards

20-minute magic links, four-hour inactive-session timeout, account lockout after repeated failures, and session revocation when access changes.

Platform safeguards

Protection has more than one layer.

Security depends on infrastructure, application design, operating discipline, and recovery. No single control carries the whole burden.

Encryption and transport

Production traffic is forced over HTTPS with secure cookies and HTTP Strict Transport Security. Managed PostgreSQL data, database backups, and private file storage are encrypted at rest.

The file bucket blocks public access and uses server-side encryption.

Backups and recovery

Managed database recovery, logical backups, file versioning, and storage lifecycle controls provide several recovery paths. We have also restored a production logical backup into an isolated environment to verify that the data is usable.

Recovery is treated as a tested process, not just a checkbox.

Application security

Authentication and authorization paths are covered by automated tests, including cross-parish denial. Continuous integration runs the Rails test suite, browser-side tests, code-quality checks, and Brakeman static security analysis.

Public and authentication workflows also use rate limits and opaque tokens.

Privacy-conscious observability

Production health, errors, and performance are monitored so problems can be found quickly. Passwords, tokens, authorization values, contact fields, message bodies, and tokenized URLs are filtered from application telemetry.

Monitoring identifiers are minimized or hashed where practical.

AI and Volunteer

Useful context, with clear boundaries.

Volunteer can answer questions and prepare work inside withDomine, but it does not receive direct database access or permission to act on its own.

Parish-scoped context

The server selects the current parish, program, user, and permissions. The model cannot choose another tenant or query the database directly.

Human approval for writes

Messages, document uploads, and interview scheduling are prepared for review. Authorization is checked again before an approved action runs.

Auditable conversations

Messages, tool calls, and proposed actions remain in withDomine. A user can delete their own conversation and the deletion itself is recorded without retaining the conversation content.

General Volunteer processing

The conversation and the minimum tool context needed to answer are sent to OpenAI through its API. withDomine sets provider-side response storage to off. OpenAI says API data is not used for model training by default, but standard abuse-monitoring retention may still apply for up to 30 days unless separate zero-retention controls are in place.

OpenAI data controls

Catholic-source processing

When a user asks for Catholic teaching or canon-law sources, the question can be sent to Magisterium AI as a specialized tool. Its current API terms say API content is not used to develop or improve its services. General Catholic questions usually do not need participant names or other identifying details.

Magisterium API terms
A clear limit: AI output supports parish work. It does not replace the pastor, tribunal, chancery, or other competent Church authority, and a user remains responsible for reviewing the answer and its sources.

Data lifecycle

Collection, use, export, and deletion each have a place.

Privacy is not only about how data is stored. It is also about why it exists, who can use it, and what happens when the relationship ends.

  1. 01

    The parish decides what enters

    The parish controls which programs, people, documents, and staff accounts are added. The parish is responsible for obtaining permissions or consents required for participant, parent, guardian, minor, or sacramental preparation information.

  2. 02

    Data supports parish work

    We use parish data to provide, secure, support, troubleshoot, maintain, and operate the services the parish has chosen. We do not sell it.

  3. 03

    The parish can take it back out

    On request or at the end of service, withDomine provides a complete export in a commonly used, machine-readable format.

  4. 04

    Deletion has a defined end

    The customer agreement provides for deletion and confirmation within 30 days. Archival backups may remain for up to 90 days, are overwritten or deleted in the ordinary course, and are not used except for disaster recovery or legal compliance.

Incidents and assurance

Accountability matters most when something goes wrong.

Our customer agreement defines both the response we owe a parish and the financial coverage maintained behind that responsibility.

Incident notice

A parish is notified without undue delay and no later than 72 hours after we become aware of a security incident affecting its data.

Investigation and remedy

We cooperate to investigate, mitigate, and remediate the incident, and the agreement includes indemnification for qualifying provider-caused security claims.

Insurance-backed

The standard agreement requires $2 million aggregate technology E&O and cyber liability coverage, plus commercial general liability coverage.

Honest assurance, without invented badges.

withDomine does not currently represent itself as SOC 2, ISO 27001, or HIPAA certified. We will publish independent certifications only after they have been earned. Today, our assurance rests on the controls described here, operating evidence, automated tests, monitoring, insurance, and the commitments in our customer agreement.

Available on request

  • Security questionnaire responses
  • Customer agreement terms
  • Certificate of insurance
  • Architecture and data-flow discussion

Ask directly

Bring us your security and privacy questions.

We are glad to discuss your parish’s requirements, complete a questionnaire, or walk through a specific data flow with your team.

Email hello@withdomine.com

This page is a current product and security overview. It does not replace a signed customer agreement, applicable privacy notice, or legal advice. Contractual terms in a signed agreement control if they differ from this summary.