— Seguridad ng Inyong Data
Your church's records, locked down and always yours.
Member names, giving and pastoral notes are some of the most trusted information a church holds. Here is exactly how StewardTrack protects them, in plain language.
Five layers of protection
Sign-in, connection, church wall, role gate and encrypted fields.
Encrypted sensitive fields
AES-256-GCM with a separate key for each church.
It is your data
Download it whenever you like.
— Is our data safe from attackers?
Follow an attacker's path
No single lock does the job, so we stack five. Tap each layer to see what an attacker would try and what stands in the way.
The attacker tries to
Guess or reuse a stolen password, or run a bot against the sign-in page.
What stands in the way
- A Cloudflare Turnstile check on sign-in, sign-up and public forms blocks automated attacks.
- Email addresses are verified before an account can be used.
- Repeated attempts are rate-limited.
- Optional two-factor sign-in with an authenticator app, plus one-time recovery codes. For people who turn it on, a stolen password alone isn't enough.
— Encryption, up close
What your records look like inside the database
Flip the switch to see the same three members the way your team sees them, and the way they are actually stored.
| name | phone | notes | |
|---|---|---|---|
| Maria Santos | maria.santos@example.org | 0917 555 0142 | Needs visit after surgery |
| Jun dela Cruz | jun.delacruz@example.org | 0918 555 0199 | Prayer request: new job |
| Ana Reyes | ana.reyes@example.org | 0920 555 0176 | Youth leader, allergic to nuts |
Your team sees normal names and notes, because StewardTrack unlocks them on our servers for signed-in people who are allowed to see them. Sample data shown.
Three levels of keys, so one key never opens everything
- Level 1
Platform key
Held on our servers, never in the database. Its only job is to lock each church's key.
- Level 2
Your church's key
Created when your church signs up. Stored only in locked form.
- Level 3
A key per field
Worked out on demand for each kind of information (email, address, notes) and never stored.
— Industry-standard building blocks
The same proven methods enterprise software relies on
We don't invent our own security. We use well-reviewed standards that large organizations rely on.
AES-256-GCM
Encrypts sensitive fields. A widely used standard that also detects tampering.
HKDF-SHA256
Derives a separate key for each kind of information from your church's key.
HMAC-SHA256
Lets staff search encrypted names without storing them in readable form.
HTTPS + HSTS
Encrypts data in transit and tells browsers to refuse insecure connections.
Row-level security
PostgreSQL's built-in way to enforce which church can see which rows.
scrypt
Scrambles recovery codes so they can't be read back, even by us.
— Sa Inyo ang Data
Your data stays yours. Take it, or remove it.
You are never locked in. Your records belong to your church, and you can leave with them whenever you choose.
Download it
- Members as an Excel file, ready to import elsewhere.
- Giving records and finance reports as spreadsheets.
- A full church archive (members, families, giving, funds, budgets, transactions and ministries) in one file, with your encrypted fields readable.
- Available to the people you give permission to export.
Remove it
- An authorized admin can delete the church's data from the account page.
- Typing your church's name to confirm prevents accidents.
- A 30-day grace period lets you cancel if you change your mind.
- Exports and deletions are logged.
— Mga Tanong
Questions, answered honestly
Keep your church's records safe and in your hands.
Start free, no credit card.