All Systems Operational

Security, compliance, and privacy. Verified.

The EvangelOS Trust Center is your single source of truth for our security posture. Download our compliance reports, view our real-time status, and understand how we protect your ministry's data.

Request Access to Reports View System Status
Compliance Status Passing
ISO 27001In Progress
PCI-DSS Level 1Compliant
GDPRReady
Penetration TestLast run: Oct 2025

Defense in depth

Our security posture

We employ a defense-in-depth strategy to protect your data across every layer of our stack.

Encryption

Data is encrypted at rest using AES-256 and in transit via TLS 1.2+. Encryption keys are managed via Google Cloud KMS.

Access Control

We follow the Principle of Least Privilege. MFA is enforced for all employees. Production access is restricted and audited.

Vulnerability Management

We conduct automated weekly scans and annual third-party penetration tests. Critical patches are applied within 24 hours.

Report a Vulnerability →

Cloud infrastructure

Infrastructure security

EvangelOS is built on Google Cloud Platform (GCP), leveraging their world-class physical and network security.

Hosting Provider

Google Cloud Platform · Region: us-central1 (Iowa)

Physical Security

GCP data centers feature biometric access controls, 24/7 security guards, and strict video surveillance. We do not maintain our own physical servers.

Network Protection

Our VPC is isolated. We use CloudArmor WAF to protect against DDoS attacks, SQL injection, and cross-site scripting.

Business Continuity

Data is replicated across multiple availability zones. We perform hourly incremental backups and daily full backups, retained for 30 days.

Incident Response

We maintain a detailed Incident Response Plan (IRP). In the event of a breach, customers are notified within 72 hours per GDPR/CCPA requirements.

Documentation

Compliance reports

Request All Documents

ISO 27001 Certification

In Progress · Auditor: Consilium Labs

Request Access

Penetration Test Summary (2025)

Date: Oct 15, 2025 · Firm: Aikido

Request Access

PCI-DSS Attestation of Compliance (AoC)

Self-Assessment Questionnaire D

Download PDF

* Some reports require a Non-Disclosure Agreement (NDA). Access is granted at the discretion of the EvangelOS Security Team.

Request our external security audit report:

Aikido Security Audit Report

Authorized subprocessors

NamePurposeLocation
Google Cloud PlatformCloud Infrastructure & Database HostingUSA
StripePayment ProcessingUSA
SendGrid (Twilio)Transactional Email ServiceUSA
TelnyxSMS Text MessagingUSA
Vetty / MinistrySafeBackground ChecksUSA
DatadogInfrastructure Monitoring & Capacity PlanningUSA
OpenAI / Google GeminiAI Content Generation FeaturesUSA

Have a security question?

Our security team is available to answer specific questions from your IT department or board.

Contact Security Team