Legal

Security Addendum

Last updated: September 8, 2026

Current technical and organizational safeguards for Cemstree customer data.

Status: Founder-approved draft — not attorney reviewed and not a certification.

Current safeguards

  • Authenticated, organization-scoped workspaces with server-side authorization and Supabase Row Level Security.
  • Role and permission controls for ministry, finance, pastoral care, check-in, and platform administration.
  • Server-only provider credentials, private file storage, audited support access, and protected administrative actions.
  • Signed, idempotent provider webhooks and bounded imports, exports, queues, retries, and background work.
  • Release checks covering dependencies, schemas, authorization, builds, and representative browser behavior.

Incident response

Cemstree investigates suspected compromise, contains affected systems, preserves relevant evidence, assesses affected customers and data, remediates confirmed weaknesses, and documents material decisions. Customer notice follows the DPA and applicable law.

Customer responsibilities

Customers must maintain appropriate account access, prompt offboarding, device security, guardian and child-safety procedures, communication consent, staff training, and incident reporting.

Limits of this statement

Cemstree does not currently claim SOC 2, ISO 27001, or HIPAA certification; a contractual uptime percentage; 24/7 monitoring; a penetration-test attestation; a tested recovery-time commitment; or attorney approval of this addendum.

Contact

Privacy, legal, accessibility, billing, and support requests may be sent to support@cemstree.com. Security vulnerabilities, suspected unauthorized access, and abuse reports should be sent to security@cemstree.com.

Terms · Privacy · DPA · Subprocessors · Security · Acceptable use · Subscriptions · Support