Identity and access
The web portal reuses CatholicCompanionOS’s Supabase authentication, database-backed roles, permission scopes, institutional hierarchy, server authorization, and row-level security.
Security
CatholicCompanionOS treats identity, tenant boundaries, youth protection, institutional scope, and governed intelligence as core design responsibilities.
The web portal reuses CatholicCompanionOS’s Supabase authentication, database-backed roles, permission scopes, institutional hierarchy, server authorization, and row-level security.
Institution selection is revalidated on the server. Public pages have no privileged configuration, and authenticated responses are marked private and non-cacheable.
The public website and portal use managed HTTPS on Google Cloud Run. Connections to identity and application services are encrypted in transit.
Response headers, a Content Security Policy, safe redirects, server authorization, and tests for denied access help protect the web experience. Access to sensitive actions is checked on the server.
Contact support@catholiccompanionos.com for security reports. Our security.txt lists the reporting channel. This page does not authorize security testing.
CatholicCompanionOS does not claim a security certification, compliance certification, or completed independent penetration test for the current web implementation.