Trust & Security

Security at EJAD

Your church's data — people, giving, and kids ministry records — deserves the same care you give your congregation. Here's how we protect it.

TLS

Encryption in transit & at rest

Every request runs over HTTPS (TLS 1.2+). Data at rest is encrypted in the database, and sensitive fields such as integration API keys are additionally encrypted with AES-256.

2FA

Authentication

Passwords are hashed with bcrypt — we never store them in plain text. Optional two-factor authentication (TOTP) is available for every account, with configurable session timeouts and rate-limited login attempts to slow brute-force attacks.

RBAC

Role-based access control

Granular, editable permissions per role — each capability can be set to Allow, Deny, or Inherit, with per-person overrides when a role isn't specific enough. Every permission change is timestamped in the audit log.

BAK

Backups

Daily off-site snapshots, with point-in-time recovery for critical failures. On top of that, every church can export its own data at any time from Settings → Backup — you're never locked in.

PCI

Payments

All card and bank payment data is handled directly by Stripe, a PCI Service Provider Level 1 processor — the highest level of certification. EJAD never sees or stores full card numbers.

AUD

Audit & monitoring

Sensitive actions — permission changes, data exports, and admin overrides — are logged with who, what, and when. We monitor for anomalous access patterns across all customer environments.

Responsible disclosure

Found a vulnerability? Tell us first.

We take security reports seriously and will work with you in good faith to understand and resolve the issue quickly.

  • Email security@ejad.app with steps to reproduce, affected URLs, and any proof-of-concept. We'll acknowledge reports within 2 business days.
  • Give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing, modifying, or deleting data that isn't yours during testing.
  • Good-faith research conducted under this policy — without harming real customer data or disrupting service — will not result in legal action from EJAD.

Have a security
questionnaire for us?

We're glad to fill out your church's vendor security review.