Protected session cookies
Staff session-token cookies are configured as HTTP-only, same-site and secure in HTTPS environments.
Trust Centre
StewardOS uses roles, permissions, protected sessions and recorded activity to support responsible handling of ministry information. This page describes implemented controls and their current boundaries; it is not a certification.
Evidence scope · 17 August 2026
Access and authentication
Controls apply according to the route, action, role, organisation and environment involved. The presence of a control in one workflow is not presented as universal coverage.
Staff session-token cookies are configured as HTTP-only, same-site and secure in HTTPS environments.
Users can be required to provide a configured time-based code or eligible backup code during credential sign-in.
Session identifiers can be revoked for their remaining lifetime using the configured revocation store.
Login and selected public or API operations apply rate-limit controls where implemented.
Organisation memberships can carry roles with module and action-level permissions.
Protected routes and actions use server-side authentication, organisation context and permission checks.
Organisation boundaries
Membership selection, scoped queries and permission checks are used to keep operational access within the applicable organisation.
StewardOS does not claim database-level row security or independently assured tenant isolation. Organisation-scoping remains an application control that requires continued testing and review.
Activity history
Audit records can capture organisation, actor, action, entity and selected metadata for implemented administrative or operational actions.
Activity history is not described as complete, immutable, permanent or tamper-proof. Scope and retention vary with the action and applicable policy.
Browser-security controls
HTTPS deployments apply transport and response controls intended to reduce common browser risks. Headers are operational controls, not independent security assurance.
HTTPS and HSTS
Content Security Policy
Frame restrictions
Content-type protection
Referrer policy
Restricted object and base targets
Storage, recovery and lifecycle
Storage, export, retention and recovery claims are separated so an implemented interface is not mistaken for a complete operational policy.
Selected supporting-document uploads use private blob storage when the configured provider is present, with organisation and entity paths. This is not a claim that every field is separately encrypted.
Backup and recovery arrangements are being documented for publication. No backup frequency, retention, restore-test, RPO or RTO guarantee is made here.
Scoped reports and exports exist for permitted workflows. Complete account export, post-closure access, retention periods and erasure coverage remain subject to reviewed policy.
Gift Aid support
StewardOS supports declaration evidence, eligibility review and R68-style export preparation. Churches remain responsible for reviewing and submitting their claims.
Eligibility rules and regional requirements still require appropriate church review. Product workflow support does not constitute tax or legal advice.
Legal and subprocessor publication
The future Privacy Notice, Terms, Cookie Notice, DPA and subprocessor schedule are not linked from this Preview because company identity, review and publication evidence remain incomplete.
Reporting concerns
A security and privacy contact will be published only after the monitored address, handling scope and response wording are confirmed. No placeholder company or contact identity is rendered.
Trust depends on scoped evidence, clear limitations and responsible operation—not unsupported assurance language.