Security First Architecture

Your Data is
Safe & Private

We believe trust is the foundation of ministry. That's why we've built Ministry Chat with enterprise-grade security controls to protect your community's information.

Our "No Training" Guarantee

We explicitly guarantee that your data is never used to train our AI models. Your sermons, member notes, and chat history remain your intellectual property. We use API-based access to AI providers whose terms prohibit using API data for model training.

Encryption at Rest

Your integration credentials and sensitive tokens are encrypted at rest using AES-256-GCM. We use a unique initialization vector for every record, ensuring your data remains secure even in the unlikely event of a database breach.

Private AI Processing

We have a strict policy: your data is NEVER used to train our AI models. All context sent to LLMs is ephemeral and discarded after processing. Your ministry's knowledge base remains exclusively yours.

Organization Isolation

Our database uses Row Level Security (RLS) to enforce strict isolation between organizations. Every query is scoped to your organization at the database level, so data can never leak between accounts.

Comprehensive Auditing

Critical actions within your organization are recorded in an audit log. This provides accountability and visibility into administrative operations.

Automated Data Minimization

We actively minimize data retention. Sensitive fields in tool execution logs are scrubbed of PII before storage, and logs are cleaned up on a rolling 90-day retention policy.

Secure Infrastructure

Built on enterprise-grade infrastructure including Supabase and Vercel, benefiting from their SOC 2 compliance, DDoS protection, and global security standards.