The EvangelOS Trust Center is your single source of truth for our security posture. Download our compliance reports, view our real-time status, and understand how we protect your ministry's data.
Defense in depth
We employ a defense-in-depth strategy to protect your data across every layer of our stack.
Data is encrypted at rest using AES-256 and in transit via TLS 1.2+. Encryption keys are managed via Google Cloud KMS.
We follow the Principle of Least Privilege. MFA is enforced for all employees. Production access is restricted and audited.
We conduct automated weekly scans and annual third-party penetration tests. Critical patches are applied within 24 hours.
Report a Vulnerability →Cloud infrastructure
EvangelOS is built on Google Cloud Platform (GCP), leveraging their world-class physical and network security.
Hosting Provider
Google Cloud Platform · Region: us-central1 (Iowa)
GCP data centers feature biometric access controls, 24/7 security guards, and strict video surveillance. We do not maintain our own physical servers.
Our VPC is isolated. We use CloudArmor WAF to protect against DDoS attacks, SQL injection, and cross-site scripting.
Data is replicated across multiple availability zones. We perform hourly incremental backups and daily full backups, retained for 30 days.
We maintain a detailed Incident Response Plan (IRP). In the event of a breach, customers are notified within 72 hours per GDPR/CCPA requirements.
Documentation
ISO 27001 Certification
In Progress · Auditor: Consilium Labs
Penetration Test Summary (2025)
Date: Oct 15, 2025 · Firm: Aikido
PCI-DSS Attestation of Compliance (AoC)
Self-Assessment Questionnaire D
* Some reports require a Non-Disclosure Agreement (NDA). Access is granted at the discretion of the EvangelOS Security Team.
Our security team is available to answer specific questions from your IT department or board.
Contact Security Team