Security

Keep sensitive access information in the right place.

MinistryBeacon helps teams discuss readiness and next steps. This page explains safe product use without making unsupported claims about technical controls.

Protect credentials

Record that a safeguard or access review is needed; do not paste the credential or secret value into the workspace.

Keep secrets out of your workspace

MinistryBeacon is not a credential vault. Never enter passwords, API keys, private keys, MFA seeds, recovery codes, authentication or session tokens, payment card information, or other secrets. Describe the process or responsibility without sharing a secret value.

Use recommendations with review

Assessments, scores, generated policies, checklists, and reports are planning aids. They do not establish that a system has been audited, tested, certified, or approved by an insurer or regulator. Have the people responsible for your organization review material decisions.

Saved assessments and report PDFs

The saved-assessment API requires a signed-in user and checks that user’s organization access before reading or saving workspace results. The assessment report PDF route checks the session and organization access before loading a saved assessment, and rate-limits report generation.

A successful assessment report PDF response includes Cache-Control: no-store. These route-level checks describe these assessment paths only; they do not establish controls for every route or for the deployed infrastructure.

Questions or a security concern

Email ministrybeacon@polsia.app to report a concern or ask a question. This contact information does not promise a response time.

This page does not claim particular encryption, backup, monitoring, incident-response, certification, audit, penetration-testing, insurance, or compliance controls. Those details require operator verification before they can be stated.