Skip to content
Documentation

Platform

Security & data

This page explains, in plain terms, how Ecclora keeps one organization's data separate from every other, and how access within an organization is controlled. It describes what the platform actually does, not a list of certifications.

Organization isolation

Every church on Ecclora belongs to its own organization. Records such as members, attendance, giving, and events are scoped to the organization that created them, and that scoping is enforced at the database level rather than left to application code to get right on every screen. In practice, this means one church's data is not visible or reachable from another church's account, by default and without exception.

Roles and permissions

Access within an organization is controlled by role, not by who happens to know a URL. Roles are built from granular permissions rather than one all-or-nothing admin switch, so broad administrative access doesn't have to mean access to finance: Church Administrator, the broadest standard role, deliberately excludes finance permissions by default. A church that wants an administrator to also see giving records assigns that deliberately, as a second role.

Where it makes sense, access can also be narrowed below the whole organization: member access down to a campus, group, or department, and attendance, giving, and communications access down to a campus. Sensitive areas can also be kept deliberately separate from broad access entirely, Pastoral Care is its own standalone role rather than something that comes bundled with member or ministry access. See Roles & Access for the full list of standard roles and how assignment works.

Authentication

Signing in to Ecclora uses standard, modern authentication practices rather than a custom-built scheme.

Access to the platform itself, used only by WebKitchen to operate Ecclora, is entirely separate from any church organization's own access, and no organization can grant itself platform rights. Platform access has its own tiers: an owner tier with full control, an administrator tier for trusted operations staff, and a support tier with no standing access to any organization's data at all. Support staff can only reach an organization through a logged, time-limited impersonation session, so access is never longer-lived or broader than that session, and every use of it is recorded.

Audit trail

Administrative changes, changes to roles, settings, and other organization configuration, are logged. An organization's administrators can review this log under Organization Settings to see who changed what, and when.

Payment details

Where an organization connects a payment provider for online giving, Ecclora verifies the connection before it's stored, and the credential itself is never displayed back in plain text after that point. See Giving for how this is configured.

Ecclora does not currently publish third-party security certifications (such as SOC 2 or ISO 27001). If a formal compliance review is part of your organization's evaluation, reach out through Get Started and we can discuss what's relevant to you.