Skip to main content
Trust & Security

Your financial data deserves bank-grade custody

Soteria Consult handles ledgers, payroll and tax records for churches, schools, hospitals, NGOs and corporates. Every one of those records is protected by layered technical and operational controls — described here in full, without marketing gloss.

Privacy centre
TLS 1.2+On every request
AES-256Encryption at rest
18Documented controls
24hIncident notification target
Control library

Eighteen controls, described in plain language

Each control below is implemented, owned by a named individual, and produces evidence we can hand to your auditors.

Transport

SSL / TLS everywhere

Every request to Soteria properties and the client portal is served over HTTPS with modern TLS and automatic certificate renewal.

  • TLS 1.2+ with strong cipher suites only
  • HSTS with automatic HTTP → HTTPS upgrade
  • Managed certificate issuance and rotation
  • Secure, HttpOnly, SameSite session cookies
Identity

Two-factor authentication

Portal accounts can be protected with a second factor, and 2FA can be enforced organisation-wide by an administrator.

  • Authenticator app (TOTP) and email one-time codes
  • Per-organisation enforcement policy
  • Recovery codes issued at enrolment
  • Step-up challenge on sensitive administrative actions
Access

Role-based permissions

Access is granted by role, not by exception. Roles are stored server-side and evaluated on every request.

  • Owner, Admin, Manager, Analyst and Viewer roles
  • Least-privilege defaults for every new member
  • Server-enforced authorisation on all data access
  • Roles never stored in the browser or on a profile record
Assurance

Audit logs

A tamper-evident, append-only record of who did what, when, and from where — retained for the life of the engagement.

  • Sign-in, permission change and data export events
  • Actor, timestamp, IP address and user agent
  • Immutable write path — no in-app editing or deletion
  • Exportable for auditors and regulators
Resilience

Automatic backups

Client data is backed up continuously with point-in-time recovery, so a bad day never becomes a lost quarter.

  • Continuous write-ahead log archiving
  • Daily full snapshots with defined retention
  • Encrypted backup storage
  • Documented restore procedure and ownership
Resilience

Disaster recovery

A written recovery plan with tested restore paths, defined targets and a named owner per engagement.

  • Recovery point and recovery time objectives agreed per client
  • Periodic restore rehearsals with documented results
  • Redundant, geographically separated infrastructure
  • Incident communication tree and escalation path
Identity

Session management

Sessions are short-lived, revocable and visible. Users and administrators can see and terminate active devices.

  • Idle and absolute session timeouts
  • Active device and location list per user
  • One-click revoke on any session
  • Full session invalidation on password or role change
Data

Data encryption

Client financial records are encrypted in transit and at rest, with sensitive fields protected at the application layer.

  • AES-256 encryption at rest
  • TLS encryption in transit
  • Application-level encryption for high-sensitivity fields
  • Managed key storage — keys never live in source code
Perimeter

CAPTCHA & bot defence

Public forms and authentication endpoints are protected against automated abuse and credential stuffing.

  • Challenge on sign-in, registration and public forms
  • Rate limiting and progressive lockout
  • Server-side validation of every submission
  • Abuse signals fed into activity monitoring
Perimeter

Malware protection

Uploaded documents are scanned and constrained before they ever touch a reviewer's workstation.

  • Scanning of client-uploaded files
  • Strict file-type and size allow-lists
  • Isolated storage with signed, expiring download links
  • Endpoint protection across the delivery team
Engineering

Secure APIs

Every endpoint authenticates, authorises and validates. Nothing sensitive is trusted from the browser.

  • Bearer-token authentication on all private endpoints
  • Schema validation on every request payload
  • Row-level authorisation enforced in the database
  • Signed webhooks with timing-safe verification
Privacy

Cookie consent

Granular, revocable consent captured before any optional cookie is set — with the record kept.

  • Necessary, preferences, analytics and marketing categories
  • Reject-all available at the same depth as accept-all
  • Consent version and timestamp stored
  • Preferences changeable at any time from the footer
Privacy

Privacy management

A single place to see what we hold, why we hold it, and how to exercise your rights over it.

  • Documented lawful basis and retention periods
  • Access, correction, export and erasure requests
  • Sub-processor register available on request
  • Data protection contact with a defined response window
Administration

User management

Administrators invite, suspend and offboard members without raising a support ticket.

  • Invite by email with role selected at invitation
  • Immediate suspend and permanent offboard
  • Bulk review of dormant accounts
  • Every membership change written to the audit log
Administration

Admin dashboard

One console for people, roles, sessions, security posture and compliance evidence.

  • Posture summary across users, roles and 2FA coverage
  • Live session and device inventory
  • Audit log search and export
  • Policy configuration in one place
Assurance

Activity monitoring

Continuous monitoring of authentication and data-access patterns, with alerting on anomalies.

  • Failed sign-in and lockout alerting
  • New device and unusual location detection
  • Bulk export and mass-read alerts
  • Alerts routed to named administrators
Identity

Password policies

Modern, evidence-based password rules — length and breach screening over arbitrary complexity theatre.

  • Minimum length with breached-password screening
  • Server-side hashing with a slow, salted algorithm
  • Configurable rotation and re-use restrictions
  • Verified current password required on change
Assurance

Compliance reporting

Evidence packs your auditors will accept, produced from live system records rather than reconstructed after the fact.

  • Access reviews and role attestation reports
  • Audit log extracts for a defined period
  • Control narratives mapped to your framework
  • Reports scheduled or generated on demand

Domains covered · Transport · Identity · Access · Data · Perimeter · Privacy · Administration · Assurance · Resilience · Engineering

How we build

Security principles we refuse to trade away

Principles are only useful when they constrain decisions. These constrain ours.

01

Least privilege by default

New members receive the narrowest role that lets them work. Elevation is explicit, time-aware and logged.

02

Defence in depth

Perimeter, application, database and operational controls each assume the layer in front of them may fail.

03

Secure by default configuration

Encryption, row-level authorisation and audit logging are switched on at provisioning, not added later.

04

Segregation of duties

Preparation, review and approval sit with different people. No single individual can move value unobserved.

05

Evidence over assertion

Every control we claim produces a record. If it cannot be evidenced, we do not present it as a control.

06

Tested recovery

Backups are only credible once restored. Restore rehearsals are scheduled, not improvised during an incident.

If something goes wrong

Incident response, from detection to written review

No provider can promise nothing will ever happen. We can promise exactly what happens next.

01

Detect

Monitoring, alerting and client reports feed a single intake channel.

02

Triage

Severity assigned within the hour; a named incident lead takes ownership.

03

Contain

Access revoked, sessions invalidated and affected systems isolated.

04

Notify

Affected clients informed with facts, scope and interim mitigations.

05

Remediate

Root cause fixed, controls strengthened, evidence retained.

06

Review

Written post-incident report with actions, owners and dates.

Found a vulnerability in a Soteria property? Report it to soteriaconsultltd@gmail.com. We acknowledge reports within one business day and will not pursue researchers acting in good faith.

Questions

What procurement teams ask us

Straight answers to the questions that hold up vendor onboarding.

Read the privacy centre
Vendor due diligence

Send us your security questionnaire

A senior partner and our security lead will complete it, walk your team through the control library, and provide the evidence pack your auditors need.