Skip to main content

Trust Centre

Clear controls for responsible ministry operations.

StewardOS uses roles, permissions, protected sessions and recorded activity to support responsible handling of ministry information. This page describes implemented controls and their current boundaries; it is not a certification.

Evidence scope · 17 August 2026

Product
StewardOS application and public Preview
Evidence
Repository implementation, tests and deployed headers
Status
Preview review · Production publication not approved
Exclusions
No certification, penetration-test or complete-control claim

Access and authentication

Layered controls around staff access.

Controls apply according to the route, action, role, organisation and environment involved. The presence of a control in one workflow is not presented as universal coverage.

Protected session cookies

Staff session-token cookies are configured as HTTP-only, same-site and secure in HTTPS environments.

TOTP availability

Users can be required to provide a configured time-based code or eligible backup code during credential sign-in.

Session revocation

Session identifiers can be revoked for their remaining lifetime using the configured revocation store.

Rate limiting

Login and selected public or API operations apply rate-limit controls where implemented.

Configurable roles

Organisation memberships can carry roles with module and action-level permissions.

Server-side checks

Protected routes and actions use server-side authentication, organisation context and permission checks.

Organisation boundaries

Application access is resolved within an organisation context.

Membership selection, scoped queries and permission checks are used to keep operational access within the applicable organisation.

StewardOS does not claim database-level row security or independently assured tenant isolation. Organisation-scoping remains an application control that requires continued testing and review.

Activity history

Selected actions create reviewable records.

Audit records can capture organisation, actor, action, entity and selected metadata for implemented administrative or operational actions.

Activity history is not described as complete, immutable, permanent or tamper-proof. Scope and retention vary with the action and applicable policy.

Browser-security controls

Deployed responses apply defensive browser policies.

HTTPS deployments apply transport and response controls intended to reduce common browser risks. Headers are operational controls, not independent security assurance.

HTTPS and HSTS

Content Security Policy

Frame restrictions

Content-type protection

Referrer policy

Restricted object and base targets

Storage, recovery and lifecycle

Publish the implemented boundary—and leave unverified guarantees out.

Storage, export, retention and recovery claims are separated so an implemented interface is not mistaken for a complete operational policy.

Partially verified

Selected private files

Selected supporting-document uploads use private blob storage when the configured provider is present, with organisation and entity paths. This is not a claim that every field is separately encrypted.

Evidence incomplete

Backups and recovery

Backup and recovery arrangements are being documented for publication. No backup frequency, retention, restore-test, RPO or RTO guarantee is made here.

Limited

Export, retention and deletion

Scoped reports and exports exist for permitted workflows. Complete account export, post-closure access, retention periods and erasure coverage remain subject to reviewed policy.

Gift Aid support

Prepare evidence and exports without replacing church review.

StewardOS supports declaration evidence, eligibility review and R68-style export preparation. Churches remain responsible for reviewing and submitting their claims.

No HMRC approval or automatic submission claim

Eligibility rules and regional requirements still require appropriate church review. Product workflow support does not constitute tax or legal advice.

Legal and subprocessor publication

Legal destinations stay unavailable until their checklist passes.

The future Privacy Notice, Terms, Cookie Notice, DPA and subprocessor schedule are not linked from this Preview because company identity, review and publication evidence remain incomplete.

Reporting concerns

A dedicated reporting channel still requires operational confirmation.

A security and privacy contact will be published only after the monitored address, handling scope and response wording are confirmed. No placeholder company or contact identity is rendered.

Review governance alongside the product and its commercial boundaries.

Trust depends on scoped evidence, clear limitations and responsible operation—not unsupported assurance language.