AskMyChurch ← Back to site

Security

Current as of June 18, 2026. We may update this page; the date reflects the latest version.

Plain answers to the questions an IT team actually asks. Where we don't have something, this page says so. We would rather publish a short true page than a long impressive one.

How it's built

Encryption

Everything we store lives on Cloudflare's infrastructure and is encrypted at rest: object storage with AES-256, key-value storage with AES-256-GCM. Everything in transit, between your visitors and the assistant and inside our systems, travels over TLS.

What we store, and for how long

The short version of our privacy policy, which this page never contradicts: visitor questions and answers are kept no more than 30 days, then permanently deleted. Deletion is an automatic storage rule, not a cron job someone has to remember. Sensitive or pastoral messages are never stored word-for-word at all; an anonymous category and count is written, the words are not. No name, email, IP address, or device identity is stored with any question.

Who can access your dashboard

Your dashboard is bound to your church. Sessions come from a verified email link or Google sign-in; another church's login gets a refusal, not your data. We test that attack on every build: our automated suite presents church A's credentials at church B's door and fails the build if anything comes back.

Abuse and cost controls

Per-visitor and per-church rate caps, monthly usage budgets, a fleet-wide spend ceiling with automatic shutoff, and a manual kill switch. A script hammering the chat endpoint cannot run an unbounded bill.

Deploys and change control

Production deploys run from the main branch through a test suite of 120+ files, including the crisis routing, cross-church access, and price-honesty checks. No green suite, no deploy.

Backups and continuity

Storage is replicated across Cloudflare's network. Your assistant is rebuildable from source: its configuration is version-controlled and its knowledge is your own published content. On top of that, tenant configuration is exported nightly to versioned storage, so we can restore to a known-good yesterday.

If something goes wrong

We page ourselves on failures, and an independent monitor checks the platform from outside our infrastructure about every five minutes; current and 30-day status is public at our status page. If a data breach affecting your church is confirmed, we tell you without undue delay and within 72 hours, with what we know and what to do.

For your procurement team

Our full Data Processing Addendum and security schedule is published for you to read, with a signable Word copy on request.

What we don't claim

We do not hold SOC 2, ISO 27001, or HIPAA certification, and we have not yet commissioned a third-party penetration test. When either changes, it will say so here with a date. Our infrastructure vendor, Cloudflare, publishes its own compliance certifications. If a vendor tells you their AI chat product is "SOC 2 certified," ask whether the certificate names the vendor or their host.

Report a vulnerability

Email security@visiongenesisai.com. Reports are treated as defects: acknowledged, triaged, fixed, and credited if you want the credit.

Last reviewed: August 18, 2026.

AskMyChurch is a Vision Genesis product, headquartered in Knoxville, Tennessee. · © 2026 Vision Genesis.
Questions about this page? askchurch@visiongenesisai.com