Skip to content

A parish keeps the most sensitive records there are.

Sacramental, financial, and pastoral. The things a priest is trusted with. Symphonia is built, top to bottom, so that trust is never misplaced. Here is exactly how, in plain words or in full technical detail.

lockEncrypted in transit and at restdnsA separate database per parishlock_personPastoral notes sealed to the priestfact_checkA tamper-evident audit traildownloadYour data, exportable any day
lock

Encryption, at every layer.

Nothing your parish types travels or rests in the clear. It is scrambled on the wire, scrambled on the disk, and the most sensitive fields are scrambled a third time with keys that are unique to your parish.

In transit
Every connection between a browser and Symphonia is encrypted, and once we cut a parish over we refuse to speak anything but the secure channel.
At rest
The disks that hold your parish are encrypted, so a stolen drive or a lost backup is unreadable noise.
Field-level, per parish
On top of that, the fields that matter most, contact details, notes, records, get their own lock, with a key that belongs only to your parish.
lock_person

The pastoral seal.

A priest hears things no database should ever surrender. So the confession queue and the permanent pastoral record are sealed to the confessor himself, and to no one else, by design.

Sealed to one person
Not your staff, not an interim priest, not a database dump, and not our own support team can open a sealed pastoral note. Only the priest it belongs to.
Append-only by nature
The pastoral record is written to, not painted over. Its history stays intact, and it transfers priest-to-priest deliberately, never by accident.
Redacted from support
If you ever ask us for help, confession content stays hidden from us unless you deliberately, temporarily lift the veil.
dns

One parish, one vault.

Your parish is not a row in a giant shared spreadsheet next to a thousand other parishes. It lives in its own database, walled off from everyone else.

Isolated by database
Each parish gets its own vault. There is no query that can reach across parishes, because the data simply is not in the same place.
Row-level security
Even inside a parish, the system checks who is asking before it hands anything over, as a belt-and-suspenders backstop.
No shared blast radius
One parish can never see, change, or break another. Their days simply do not touch.
fact_check

Who can do what, and the record of it.

The rector decides who sees giving amounts and who sees pastoral notes, down to the person. And every sensitive thing anyone does is written into a log that cannot be quietly rewritten.

Real roles, real limits
Rector, treasurer, secretary, chanter, each role sees exactly what it should, especially around money and pastoral care.
A record that cannot lie
Exports, downloads, deletions, opening someone's giving, all of it is logged, and the log is built so a tampered entry shows.
Two hands on the lever
The truly destructive actions, wiping records in bulk, take a deliberate second confirmation, so no single slip or single bad actor can erase your parish.
https

Getting in.

Passwords are stored so even we cannot read them, a second code is asked at sign-in, and a parish can turn on Face ID and Touch ID for the people who want it.

Passwords we cannot read
Your password is never stored as itself. Even in a worst-case leak, there is nothing to read.
A second factor
Signing in asks for a code sent to your email, so a stolen password alone is not enough.
Face ID and Touch ID
Parishes that want it can sign in with a fingerprint or a face, no password to fumble at the candle desk.
Brute force gets nowhere
Guessing at the door gets you locked out fast, not in.
support_agent

When we help, the lights stay on.

If our support ever steps into your parish to help, it is with the lights on: we cannot silently change your data, pastoral content is hidden from us, and every session is written down for you to see.

We cannot write as you
While we are assisting, the system will not let us change your records. We can look to help; we cannot act as your parish.
Pastoral stays hidden
Confession and sealed notes stay dark to us by default, even while we help with something else.
Every session, on the record
You can see exactly when someone from support was in, and what they touched.
payments

Money, handled the right way.

Giving runs through Stripe and settles straight into your parish's own account. We never see, and never store, a card or bank number.

We never touch the card
Card and bank details go straight to Stripe and never rest with us. There is nothing on our side to steal.
Funds go to the parish
The money lands in the parish's own account, not ours. We are the ledger, not the wallet.
Statements that reconcile
Every gift posts itself so the plate and the books always agree, and year-end statements are one click.
history_edu

When things go wrong.

Hard drives fail and mistakes happen. Symphonia is built so a bad day is a recoverable one, with encrypted backups kept somewhere else and a real, written plan to get you back.

Backups, encrypted and off-site
Your parish is backed up regularly, encrypted, and kept in a separate place, so one failure cannot take it all.
A real recovery target
We do not just hope. There is a written plan with a promise: back within a day, losing at most an hour.
Watched, and patched
The system is watched for anything unusual, and security fixes are applied on a schedule, not whenever someone remembers.
Told, if it ever happens
If a breach ever touched your parish, you would hear from us quickly and honestly, with what we know and what we are doing.
download

It is your data, and it stays yours.

The parish owns its record. You can take a full copy whenever you like, we never sell it, and we never train AI on it. There is no lock-in, ever.

Export any day
Members, giving history, the sacramental register, all of it, downloadable whenever you want it, in formats you can actually use.
Never sold, never mined
We do not sell your parish list, we do not run ads against it, and we do not feed it to an AI. Full stop.
Delete, with care
Ask us to delete, and we will, keeping only what the law makes us keep, and telling you exactly what and why.
check_circle

Standards, the law, and who helps run it.

Symphonia is built to meet the privacy laws a parish and its people fall under, and the short list of trusted providers behind the scenes is published, so nothing is hidden.

The laws that apply
Whether your people are in the US, Canada, or the EU, the rights those laws give them are built in, not bolted on.
Where data lives, and crosses
Parish data is processed primarily in the EU, and where a provider works from the US, it is under proper legal safeguards.
A short, published bench
A handful of vetted providers help run the service, hosting, email, payments, and the list is public and updated before it ever changes.

Every sensitive action, written down.

And impossible to quietly rewrite. Here is the rector's own view of it.

fact_checkActivityRector only
downloadFr. John exported the parishioner directorytoday · 9:14 am
account_balanceMat. Mary opened giving for the Doe householdtoday · 8:52 am
descriptionA 2025 giving statement was downloadedyesterday
fact_checkReader James’s role was changed to ChanterTue
lock_personA member record was deleted from PeopleMon
httpsHash chain verifiedImmutable · every entry linked to the last

The questions clergy actually ask.

Can you read our confession notes?No. They are sealed to the priest with encryption we cannot bypass. Not our staff, not a database dump, not a backup, and not an interim priest can open them.
What happens if Symphonia gets breached?Your most sensitive fields are encrypted with keys unique to your parish, so a breach yields ciphertext, not readable records. And we would notify you within 72 hours with what we know and what we are doing.
Where does our data physically live?Primarily on encrypted servers in the European Union, with backups kept off-site. Where a provider like Stripe operates from the US, it is under Standard Contractual Clauses or the EU-US Data Privacy Framework.
Could another parish ever see ours?No. Each parish lives in its own separate database, with row-level security as a second layer. There is no query that reaches across parishes, because the data is not in the same place.
Do you store our members’ card numbers?Never. Giving runs through Stripe, which is PCI Level 1. We store the record of the gift, not the card. There is nothing on our side to steal.
Can we get all of our data out?Any day you like. Members, giving history, and the sacramental register export to portable files on demand. The parish owns its record; we just keep it safe.
Do you sell our data or train AI on it?No, and no. We do not sell or broker personal data, we run no ad trackers in the product, and we never use parish data to train machine-learning or AI models.
What if we want to leave?Export everything and walk out, with no long-term contract. On the way out we return or securely delete your data within thirty days, keeping only what the law requires.
The paperwork, too.

Everything above is written into our policies, in plain language, written for a parish rather than a boardroom. Read them in full.