Security

What we do with your church's data.

Plain answers for the people who have to sign off on a new system: what is stored, who can see it, and what happens when something goes wrong.

Access is scoped per church

Every table enforces row-level access control in the database itself, not only in the app. A signed-in user reaches the rows belonging to their own church and nothing else. Roles are stored separately from profiles, so a user cannot raise their own privileges by editing their profile.

Workers see their own duties. Department heads see their department. Administrators see their church, and only leadership sees a consolidated view across branches.

Transport and hosting

All traffic is served over HTTPS with strict transport security, a restrictive content security policy, and a locked-down permissions policy. Data is held in a managed Postgres database with automated backups.

Email

Invitations, reminders and roster notices are sent from a dedicated sending domain with your church's verified reply-to address, so replies reach you rather than us. Every message is written to a delivery log with its status, visible to your administrators.

Deletion and recovery

Deleting a record moves it to a recovery area for 30 days, so a mistaken deletion is reversible from Settings. After that window it is removed.

Any user can delete their own account from the app. If you are the only administrator of a church, ownership must be transferred first so the church is never left unreachable.

Monitoring

Application errors and delivery failures are recorded and surfaced in the in-app health panel, and an independent external check probes the service on a schedule so an outage is detected even when the app itself is down.

What we do not claim

Oruchi holds no third-party security certification at this time, and we will not imply one. If your church requires a formal review, contact us and we will answer specific questions directly.