Security

Controls we actually run

Multi-tenant church software. Isolation, permissions, and cookies come first. Marketing badges come later, if at all.

  1. Tenant isolation

    Queries carry the church id. An API call cannot return another church’s members, giving, or sermons because a client passed a foreign id.

  2. Permission on the route

    Nest guards require a node and action. Hiding a button in the UI is not the security boundary. Platform operators sign in on a separate host.

  3. Sessions

    Live web auth uses httpOnly cookies (miqra_session and miqra_refresh). Access tokens are short-lived. Refresh rotates. Tokens are not stored in localStorage.

  4. Money as integers

    Giving and SaaS billing amounts are kobo integers on the wire. The UI does not invent a naira figure the API did not send.

  5. Sensitive pastoral data

    Pastoral notes and giving history are restricted. They are not dumped into the public directory. Export is gated.

  6. Audit log

    Admin actions, role changes, money movement, and member-data access are logged. Retention is twelve months at the platform operator.

  7. Member rights

    Nigeria Data Protection Act 2023 and the NDPR framework sit behind export and deletion paths. Churches remain controller of their member records. See Privacy and the DPA.

  8. What this page does not say

    We do not claim SOC 2, ISO 27001, or a third-party pentest on this site. When an audit exists, it will be named with a date.