Security at Koinonia Cloud

Last reviewed: May 22, 2026

Koinonia Cloud holds the personal information of your church family — members, families, children, financial gifts. We treat that data as sacred. This page documents the technical and operational measures we use to protect it, and the shared-responsibility model we operate under with subscribing churches.

For the full legal language, see our Terms of Service (§7 Shared Responsibility) and Privacy Policy (§5 Data Storage and Security).


1. Architecture — Single-Tenant Isolation

Every subscribing church receives its own dedicated instance on Google Cloud Platform:

No data, credentials, or configuration are shared between churches. A vulnerability or misconfiguration affecting one church instance cannot reach another. There is no “noisy neighbour” problem, and no cross-tenant query path exists in our codebase.

2. Encryption

StateStandard
Data at restAES-256, using Google-managed encryption keys (CMEK available on request for enterprise tiers)
Data in transitTLS 1.2 or higher between browser, application, and database
BackupsEncrypted with the same standards as production data

3. Access Controls

4. Backups

5. Incident Response

In the event of a data breach affecting your church's data, we will:

  1. Notify your SuperAdmin via email within seventy-two (72) hours of discovery
  2. Provide details of the nature and scope of the breach
  3. Describe the measures taken to contain and remediate the incident
  4. Cooperate with your organisation's own notification obligations under applicable law

Report a suspected security issue: support@koinoniacloud.com.

6. Sub-Processors

We use the following service providers, each subject to contractual data-protection obligations:

ProviderPurposeData Accessed
Google Cloud PlatformInfrastructure hosting, database, storage, backupsAll Subscriber Data (encrypted)
StripeSubscription billing for your church's Koinonia Cloud planChurch billing info only — not member data
PostmarkTransactional email deliveryEmail addresses, message content
TwilioSMS messaging (if enabled by your church)Phone numbers, message content

When your church connects its own payment processor (Stripe Connect, PayPal, Square) for donation processing, transactions flow directly between your members and your payment processor account. We do not process, store, or have access to donors' payment card information.

7. Compliance Posture

8. Shared Responsibility Model

Strong security requires both sides of the platform to do their part. Here is how the responsibilities split:

What we are responsible for

What you (the subscribing church) are responsible for

9. Reporting a Vulnerability

If you believe you have found a security vulnerability in Koinonia Cloud, please email support@koinoniacloud.com with “Security” in the subject line, plus a description and reproduction steps. We commit to:

Please give us a reasonable window to fix the issue before any public disclosure.

10. Questions

For security questions or to request additional documentation (sub-processor list, compliance attestations, architecture review), email support@koinoniacloud.com — a real human will route it to the right place.