Security
Your Financial Data, Protected
OCM is built with layered security controls. We take the protection of parish financial data seriously.
Encryption
Data Encryption
- Provider-managed encryption for hosted data and encrypted network connections
- Database hosted on Railway with access restricted through application and platform controls
Payments
Payment Security
- Payments processed by Stripe (PCI DSS Level 1 certified)
- Bank connections via Plaid (SOC 2 Type II, end-to-end encryption)
- OCM never stores raw credit card numbers or bank credentials
Access
Access Controls
- Role-based access control with scoped application roles
- Configurable approvals and access controls support separation of duties
- Configurable approval thresholds per user
- Security-sensitive and financial actions produce protected audit records
Authentication
Authentication
- Powered by Clerk (SOC 2 Type II)
- Multi-factor authentication available
- Session management with automatic timeout
- Biometric login on mobile (fingerprint, Face ID)
Compliance
Compliance
- Double-entry fund accounting designed to support nonprofit reporting workflows
- Financial activity records preserve actor or source attribution where applicable
- Immutable audit log (UPDATE/DELETE revoked at database level)
- Year-end audit export packages
Infrastructure
Infrastructure
- PostgreSQL 18 database with forced row-level security
- API-first architecture with JWT authentication
- Shared platform with database-enforced entity-level tenant isolation
- Independent encrypted backup and point-in-time recovery controls are pre-pilot launch gates
Questions about security?
Use our contact form for security questions while our dedicated reporting channel is being verified.