Trust & Security
Security at EJAD
Your church's data — people, giving, and kids ministry records — deserves the same care you give your congregation. Here's how we protect it.
Encryption in transit & at rest
Every request runs over HTTPS (TLS 1.2+). Data at rest is encrypted in the database, and sensitive fields such as integration API keys are additionally encrypted with AES-256.
Authentication
Passwords are hashed with bcrypt — we never store them in plain text. Optional two-factor authentication (TOTP) is available for every account, with configurable session timeouts and rate-limited login attempts to slow brute-force attacks.
Role-based access control
Granular, editable permissions per role — each capability can be set to Allow, Deny, or Inherit, with per-person overrides when a role isn't specific enough. Every permission change is timestamped in the audit log.
Backups
Daily off-site snapshots, with point-in-time recovery for critical failures. On top of that, every church can export its own data at any time from Settings → Backup — you're never locked in.
Payments
All card and bank payment data is handled directly by Stripe, a PCI Service Provider Level 1 processor — the highest level of certification. EJAD never sees or stores full card numbers.
Audit & monitoring
Sensitive actions — permission changes, data exports, and admin overrides — are logged with who, what, and when. We monitor for anomalous access patterns across all customer environments.
Responsible disclosure
Found a vulnerability? Tell us first.
We take security reports seriously and will work with you in good faith to understand and resolve the issue quickly.
- Email security@ejad.app with steps to reproduce, affected URLs, and any proof-of-concept. We'll acknowledge reports within 2 business days.
- Give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing, modifying, or deleting data that isn't yours during testing.
- Good-faith research conducted under this policy — without harming real customer data or disrupting service — will not result in legal action from EJAD.
Related
More on how we handle data.
Have a security
questionnaire for us?
We're glad to fill out your church's vendor security review.