Security
Your church's data is sacred to us. Pastoral notes, children's records, giving history, counselling conversations. Security is not a feature we added - it is built into how Floways works at every level.
We're an Australian company. Your data lives in Australia. Our engineering team is held to the standards we'd want for our own families' churches.
Infrastructure
| Area | Details |
|---|---|
| Hosting | AWS Sydney (ap-southeast-2), exclusively |
| Data residency | All AU/NZ customer data stored in Australia |
| Encryption at rest | AES-256 across all storage, managed via AWS Key Management Service |
| Encryption in transit | TLS 1.2+ on all connections; TLS 1.3 preferred |
| Backups | Continuous point-in-time recovery within ~5 minutes; daily snapshots retained 35 days; weekly snapshots retained 90 days |
| Single-tenant restore | We can restore your data to a point in time without affecting any other church |
Tenant isolation
Floways uses one PostgreSQL database per church - not a shared database with a tenant ID column. There is no shared “members” table containing rows for multiple churches. A bug, an SQL injection vulnerability, or a compromised credential in one church's tenant cannot reach another church's data, because the connection is to a different database entirely.
This is unusual in church management software, and it's deliberate.
Authentication and access
- Multi-Factor Authentication (MFA) is supported via three methods: authenticator app (TOTP), SMS one-time code, and Email one-time code. We strongly recommend TOTP - the most secure of the three - for any account with admin or financial access.
- Passwords are never stored in plain text. We use industry-standard hashing.
- Session tokens expire automatically after inactivity.
- Role-based access control with granular per-module permissions, scoped to the organisational hierarchy (“Spaces”) inside the platform.
- The Church Super Admin role is protected and cannot be deleted.
- All API endpoints require authentication by default. Permissions are enforced at the application layer, not just the user interface.
AI and data privacy
All AI inference in Floways runs server-side within our backend boundary in Sydney. Your data is never sent to an AI provider in a way that allows the provider to retain it or use it to train models.
We do not train AI models on your data. We do not opt into any AI provider's training programme. AI features can be disabled at the module or organisation level if your church prefers.
AI API keys are stored in secure secret management and are never accessible from a browser, a frontend bundle, or an end user.
Payment security
Floways does not store raw card numbers, CVVs, or bank account credentials at any point. All payment processing is handled by PCI-DSS Level 1 compliant processors - the highest tier, audited annually. Card details are entered via the processor's secure tokenisation widget; Floways stores only a token reference, the last four digits, and the card brand.
This places Floways' direct PCI-DSS scope at SAQ-A - the lightest tier - by design.
Application security
- All code changes are peer-reviewed before deployment.
- Architectural changes require written review and sign-off by our Senior Systems Architect.
- Automated dependency scanning, secret scanning, and security analysis run as part of our deployment pipeline.
- Production access is limited to a small number of named engineers under MFA.
Incident response
In the event of a security incident affecting your data:
- We will notify affected customers promptly, and in any event no later than 24 hours after we confirm the incident.
- The notification will include the nature of the incident, what data was affected, and the steps we are taking.
- We comply with mandatory data breach notification requirements under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme.
- We notify the Office of the Australian Information Commissioner (OAIC) where the law requires, within statutory timeframes.
To report a security issue, contact security@floways.co.
Data ownership and exit
Your data is yours. You can export it at any time as JSON or CSV - at no charge.
On termination, your data is retained in read-only state for 90 days, with notifications at the 30-day and 7-day marks before permanent and irreversible deletion. See our Privacy Policy for full details.
Subprocessors
We share data only with service providers necessary to operate Floways - cloud hosting, payment processing, email and SMS delivery, AI inference, and error monitoring. Each provider is contractually bound to security and confidentiality standards equivalent to ours. The categories are listed in our Privacy Policy. The named-vendor register is available on request.
Your responsibilities
Security is a shared responsibility. We recommend:
- Enabling MFA on all Floways user accounts (TOTP preferred)
- Using strong, unique passwords
- Reviewing user access regularly and removing accounts for staff who have left
- Contacting us immediately at security@floways.co if you suspect unauthorised access
Security questionnaires and procurement reviews
If your church or denomination requires a security questionnaire response or a deeper review, we have a Security, Data Handling & Breach Response Framework - the document our engineering team operates against - available under NDA. Email security@floways.co.
Questions about security: security@floways.co
Vinteract Pty Ltd t/a Floways · Adelaide, South Australia · Last updated: 4 May 2026