Security

Your Financial Data, Protected

OCM is built with layered security controls. We take the protection of parish financial data seriously.

Encryption

Data Encryption

  • Provider-managed encryption for hosted data and encrypted network connections
  • Database hosted on Railway with access restricted through application and platform controls

Payments

Payment Security

  • Payments processed by Stripe (PCI DSS Level 1 certified)
  • Bank connections via Plaid (SOC 2 Type II, end-to-end encryption)
  • OCM never stores raw credit card numbers or bank credentials

Access

Access Controls

  • Role-based access control with scoped application roles
  • Configurable approvals and access controls support separation of duties
  • Configurable approval thresholds per user
  • Security-sensitive and financial actions produce protected audit records

Authentication

Authentication

  • Powered by Clerk (SOC 2 Type II)
  • Multi-factor authentication available
  • Session management with automatic timeout
  • Biometric login on mobile (fingerprint, Face ID)

Compliance

Compliance

  • Double-entry fund accounting designed to support nonprofit reporting workflows
  • Financial activity records preserve actor or source attribution where applicable
  • Immutable audit log (UPDATE/DELETE revoked at database level)
  • Year-end audit export packages

Infrastructure

Infrastructure

  • PostgreSQL 18 database with forced row-level security
  • API-first architecture with JWT authentication
  • Shared platform with database-enforced entity-level tenant isolation
  • Independent encrypted backup and point-in-time recovery controls are pre-pilot launch gates

Questions about security?

Use our contact form for security questions while our dedicated reporting channel is being verified.