Security
How we protect your association's data
A plain-language overview of the safeguards built into Civic Quarters.
Each community's data is isolated
Records are scoped to a single community and enforced by row-level security in the database, so one association can never read another's residents, ledger or documents — even if application code had a bug.
Encryption in transit
All traffic to Civic Quarters uses HTTPS (TLS). Documents are stored in private storage with access checks.
Card and bank details never touch our servers
Payments are processed by Stripe. Card numbers and bank account details go directly to Stripe and are never stored by Civic Quarters.
AI providers don't train on your data
Civic Brain sends only the passages needed to answer a question to AI providers under terms that do not allow training on customer data.
Backups and audit history
The database is backed up automatically. Financial entries are immutable and corrected only by reversing entries, and admin actions are recorded in an audit log.
Reporting a security issue
Email security@civicquarters.com. We acknowledge reports within two business days.
