Civic Quarters

Security

How we protect your association's data

A plain-language overview of the safeguards built into Civic Quarters.

Each community's data is isolated

Records are scoped to a single community and enforced by row-level security in the database, so one association can never read another's residents, ledger or documents — even if application code had a bug.

Encryption in transit

All traffic to Civic Quarters uses HTTPS (TLS). Documents are stored in private storage with access checks.

Card and bank details never touch our servers

Payments are processed by Stripe. Card numbers and bank account details go directly to Stripe and are never stored by Civic Quarters.

AI providers don't train on your data

Civic Brain sends only the passages needed to answer a question to AI providers under terms that do not allow training on customer data.

Backups and audit history

The database is backed up automatically. Financial entries are immutable and corrected only by reversing entries, and admin actions are recorded in an audit log.

Reporting a security issue

Email security@civicquarters.com. We acknowledge reports within two business days.