Parish boundaries
Parish-owned records are tenant-scoped on the server. Requests resolve the active parish before protected data is read or changed, and cross-parish access is denied.
Security & Privacy
withDomine is built so parish teams can work with sensitive formation records without giving up ownership or control. Here is how we protect access, limit use, preserve accountability, and respond when something goes wrong.
Owned by your parish
Parish data remains the property of the parish.
Not sold
We do not sell parish data or use it for advertising.
Encrypted
Production data is encrypted in transit and at rest.
Portable
A complete, machine-readable export is available by request.
Our commitments
Our customer agreement turns the core privacy promises into specific obligations, not just marketing language.
withDomine is responsible for
The parish is responsible for
Access and identity
A person must be authenticated, belong in the current parish context, and be authorized for the requested action. Each layer is checked on the server.
Parish-owned records are tenant-scoped on the server. Requests resolve the active parish before protected data is read or changed, and cross-parish access is denied.
Directors, staff, volunteers, sponsors, and participants do not receive the same access. Server-side policies and explicit grants can limit access by ministry, program, cohort, assignment, and capability.
withDomine supports password, short-lived magic link, Google, and Microsoft sign-in. Login attempts are rate-limited, repeated failures lock accounts, and inactive sessions expire.
Sensitive document previews and downloads pass through authorized application routes and create an access record. Important changes preserve actor, parish, time, and request context.
Current sign-in safeguards
20-minute magic links, four-hour inactive-session timeout, account lockout after repeated failures, and session revocation when access changes.
Platform safeguards
Security depends on infrastructure, application design, operating discipline, and recovery. No single control carries the whole burden.
Production traffic is forced over HTTPS with secure cookies and HTTP Strict Transport Security. Managed PostgreSQL data, database backups, and private file storage are encrypted at rest.
The file bucket blocks public access and uses server-side encryption.
Managed database recovery, logical backups, file versioning, and storage lifecycle controls provide several recovery paths. We have also restored a production logical backup into an isolated environment to verify that the data is usable.
Recovery is treated as a tested process, not just a checkbox.
Authentication and authorization paths are covered by automated tests, including cross-parish denial. Continuous integration runs the Rails test suite, browser-side tests, code-quality checks, and Brakeman static security analysis.
Public and authentication workflows also use rate limits and opaque tokens.
Production health, errors, and performance are monitored so problems can be found quickly. Passwords, tokens, authorization values, contact fields, message bodies, and tokenized URLs are filtered from application telemetry.
Monitoring identifiers are minimized or hashed where practical.
AI and Volunteer
Volunteer can answer questions and prepare work inside withDomine, but it does not receive direct database access or permission to act on its own.
The server selects the current parish, program, user, and permissions. The model cannot choose another tenant or query the database directly.
Messages, document uploads, and interview scheduling are prepared for review. Authorization is checked again before an approved action runs.
Messages, tool calls, and proposed actions remain in withDomine. A user can delete their own conversation and the deletion itself is recorded without retaining the conversation content.
The conversation and the minimum tool context needed to answer are sent to OpenAI through its API. withDomine sets provider-side response storage to off. OpenAI says API data is not used for model training by default, but standard abuse-monitoring retention may still apply for up to 30 days unless separate zero-retention controls are in place.
OpenAI data controlsWhen a user asks for Catholic teaching or canon-law sources, the question can be sent to Magisterium AI as a specialized tool. Its current API terms say API content is not used to develop or improve its services. General Catholic questions usually do not need participant names or other identifying details.
Magisterium API termsData lifecycle
Privacy is not only about how data is stored. It is also about why it exists, who can use it, and what happens when the relationship ends.
The parish controls which programs, people, documents, and staff accounts are added. The parish is responsible for obtaining permissions or consents required for participant, parent, guardian, minor, or sacramental preparation information.
We use parish data to provide, secure, support, troubleshoot, maintain, and operate the services the parish has chosen. We do not sell it.
On request or at the end of service, withDomine provides a complete export in a commonly used, machine-readable format.
The customer agreement provides for deletion and confirmation within 30 days. Archival backups may remain for up to 90 days, are overwritten or deleted in the ordinary course, and are not used except for disaster recovery or legal compliance.
Incidents and assurance
Our customer agreement defines both the response we owe a parish and the financial coverage maintained behind that responsibility.
A parish is notified without undue delay and no later than 72 hours after we become aware of a security incident affecting its data.
We cooperate to investigate, mitigate, and remediate the incident, and the agreement includes indemnification for qualifying provider-caused security claims.
The standard agreement requires $2 million aggregate technology E&O and cyber liability coverage, plus commercial general liability coverage.
withDomine does not currently represent itself as SOC 2, ISO 27001, or HIPAA certified. We will publish independent certifications only after they have been earned. Today, our assurance rests on the controls described here, operating evidence, automated tests, monitoring, insurance, and the commitments in our customer agreement.
Available on request
Ask directly
We are glad to discuss your parish’s requirements, complete a questionnaire, or walk through a specific data flow with your team.
This page is a current product and security overview. It does not replace a signed customer agreement, applicable privacy notice, or legal advice. Contractual terms in a signed agreement control if they differ from this summary.