Security & Trust

Built so the sensitive things never reach us.

This page describes how Stewardvine is actually architected — not certifications we don't hold. Card data and donor funds are handled by Square and Apple; Stewardvine holds only what it needs to run the software.

Stewardvine never sees, transmits, or stores card numbers, CVV, or magnetic-stripe data.

Card data is captured inside Apple's Secure Element via Tap to Pay on iPhone and encrypted directly to Square, our payment processor, on a PCI-validated solution. It never touches Stewardvine's servers. [to be finalized]

Shared responsibility

Who protects what

Square

Card data capture-to-encryption, payment processing, settlement, and card-network compliance. Funds settle into the parish's own Square account.

Apple

Tap to Pay on iPhone and the Secure Element that reads the card on the device, so the number is never exposed to the app.

Stewardvine

Donation metadata, receipts, parish-admin accounts, and encrypted OAuth tokens. No card data. No custody of funds.

Controls

What is live today

We list only controls that are actually in place. Anything still planned is labeled a roadmap item — never presented as done.

Live

Encryption

Encryption in transit (TLS 1.2+/1.3) and at rest (AES-256). OAuth tokens are stored encrypted. [to be finalized]

Live

Access & accounts

Multi-factor authentication, least-privilege roles for parish admins, and audit logging of administrative actions.

Live

Least-privilege access to Square

Stewardvine requests only the Square permissions it needs to accept payments — no balance, transfer, or payout scopes — reinforcing that Stewardvine cannot move or redirect your funds.

Roadmap

SOC 2 Type II

SOC 2 Type II is planned, and Stewardvine is architected to the AICPA Trust Services Criteria. We do not claim SOC 2 today. August 13, 2026

Your donor data is yours

You can export your donor and donation records at any time — including if you ever leave Stewardvine. Stewardvine does not sell or share donor data. Because your funds and Square account are the parish's, your giving continues independently of Stewardvine.

Read the Privacy Policy →

If something goes wrong

Stewardvine maintains an incident-response process and commits to notifying an affected parish promptly so both parties can meet resident-notification and regulator deadlines. [to be finalized]

See the Data Processing Addendum →

Subprocessors

Who helps us run the service

We publish the vendors that process data on our behalf, with a commitment to notify parishes of material changes before a new subprocessor begins processing.

Current subprocessors (illustrative — finalize to match the real stack).
SubprocessorPurposeLocation
Square (Block, Inc.)Payment processing & settlement (Stewardvine never receives card data or funds)United States
[to be finalized]Application hosting — donation metadata, admin accounts, encrypted tokens[to be finalized]
Apple Push Notification serviceApp notificationsUnited States
[to be finalized]Receipts, confirmations, and account emailUnited States
[to be finalized]Reliability & error monitoringUnited States

Full subprocessor list & change-notice policy →

Security Overview

A one-page summary for your finance council or diocesan reviewer.

Download (PDF) — [to be finalized]

Insurance

E&O and cyber Certificates of Insurance are available to prospective customers on request. [to be finalized]

Diocesan requirements →

Report a vulnerability

Found a security issue? Please tell us directly.

hello@stewardvine.com

Effective date August 13, 2026 · Change log [to be finalized] — this page is updated as controls change; roadmap items are dated when they go live.

Book a Demo

Bring your security questions.

We're glad to walk a finance council or diocesan reviewer through the architecture in detail.