Security

Security is part of the operating architecture.

CatholicCompanionOS treats identity, tenant boundaries, youth protection, institutional scope, and governed intelligence as core design responsibilities.

01

Identity and access

The web portal reuses CatholicCompanionOS’s Supabase authentication, database-backed roles, permission scopes, institutional hierarchy, server authorization, and row-level security.

02

Data and tenant boundaries

Institution selection is revalidated on the server. Public pages have no privileged configuration, and authenticated responses are marked private and non-cacheable.

03

Encryption in transit

The public website and portal use managed HTTPS on Google Cloud Run. Connections to identity and application services are encrypted in transit.

04

Layered web defense

Response headers, a Content Security Policy, safe redirects, server authorization, and tests for denied access help protect the web experience. Access to sensitive actions is checked on the server.

05

Responsible disclosure

Contact support@catholiccompanionos.com for security reports. Our security.txt lists the reporting channel. This page does not authorize security testing.

06

Claims and assurance

CatholicCompanionOS does not claim a security certification, compliance certification, or completed independent penetration test for the current web implementation.

Continue exploring CatholicCompanionOS.