Grace Unworthy Ministries, LLC
Security Policy
Effective Date: June 21, 2026
Last Updated: July 26, 2026
Document URL: https://graceunworthy.com/legal/security
Download PDF generates a letter-size Times document with page numbers. Print uses your browser's print dialog.
1. Introduction & Scope
Grace Unworthy Ministries, LLC ("we," "our," or "us") operates multiple web properties and services. This document applies to the properties listed in our Covered Properties notice, which is incorporated by reference.
This Security Policy describes, in general terms, the technical and organizational measures we use to protect information across our websites, learning platforms, e-commerce systems, and The Story Haven community and mobile applications. It supplements our Privacy Policy and Terms of Service.
This document is a description of our current practices, not a warranty or guarantee. Our practices change over time as our systems evolve, and this page may not reflect every technical detail of every service at every moment.
2. Infrastructure
Our production services run on established cloud infrastructure providers. Our current stack includes:
- Cloudflare: DNS, TLS termination at the edge, CDN delivery, bot mitigation, and distributed denial-of-service (DDoS) protection
- Google Cloud Platform / Google Kubernetes Engine (GKE): container orchestration, application hosting, and the managed database environment for our primary application data
- Network separation: public-facing services are separated from internal and administrative systems, and database access is restricted to application workloads
- Backups: database backups are taken on a regular schedule and retained for a limited period
We rely on the physical, environmental, and platform-level security controls maintained by these providers. We do not operate a formal, independently certified security audit or certification program of our own, and we do not claim SOC 2, ISO 27001, or similar attestations for our applications.
3. Application Security
Within our applications, we use the following controls:
- Password hashing: account passwords are hashed with bcrypt and are never stored in plain text or in a reversible form
- Token-based authentication: signed JSON Web Tokens (JWT) with expiration, together with session and token revocation on logout or credential change
- Role-based access control (RBAC): administrative and sensitive operations are restricted by role and business account context
- Rate limiting: throttling on authentication and other sensitive endpoints to limit brute-force and abuse attempts
- Turnstile CAPTCHA: Cloudflare Turnstile challenges on registration, sign-in, and public form submissions
- Input validation and HTML sanitization: schema validation on API requests and sanitization of user-submitted HTML and rich text before storage or display
- Content Security Policy (CSP): browser-level restrictions on script and resource origins for our web applications
- Audit logging: logging of significant administrative actions
4. Data Protection & Encryption
We protect data in transit and, where applicable, at rest:
- In transit: traffic between your browser or mobile app and our services is encrypted using TLS. Internal service traffic travels within our cloud provider's network.
- At rest: our primary database and backups are hosted on Google Cloud Platform, and media and file uploads are stored with Cloudinary and Amazon Web Services (S3). Encryption at rest is provided by those platforms where they offer it as a default or configured feature.
- Application-level encryption: certain fields — including some message content and stored integration tokens — are additionally encrypted by our application using AES-GCM before being written to the database.
- Payment data: card numbers are processed directly by our PCI-compliant payment processor. We do not store full payment card numbers on our servers.
5. The Story Haven & Mobile Applications
The Story Haven web community and mobile applications involve some additional considerations:
- Device tokens: when you enable notifications, we store a push notification device token so we can deliver messages through Expo push services (iOS and Android) and web push. Tokens are removed when you sign out or disable notifications, and may be purged when a provider reports them as invalid.
- On-device credential storage: mobile authentication tokens are stored using the platform's secure storage (Keychain on iOS, Keystore on Android) where available.
- User content: posts, comments, images, and audio are stored on our hosted infrastructure and served over HTTPS. Content shared with a group or with the community is visible to the audience you select.
- Moderation and safety tools: members can report content, block other members, and contact us about abuse. See Privacy Policy for how we use this information.
6. Third-Party Service Providers
We rely on third-party providers to operate our services. Each provider receives only the data needed to perform its function, and each is governed by its own terms and privacy practices. Our principal providers include:
- Stripe: payment processing and subscription billing
- Postmark: transactional and marketing email delivery
- Twilio: SMS and text message delivery
- OpenAI: AI-assisted content and support features
- AssemblyAI: audio transcription for podcast and media content
- Cloudinary: image and media storage, transformation, and delivery
- Amazon Web Services (S3): file and document storage
- Cloudflare: DNS, CDN, edge security, and Turnstile
- Sentry: application error monitoring and diagnostics
- EasyPost: shipping labels and delivery tracking for physical orders
For a fuller description of what each category of provider receives and why, see our Privacy Policy.
7. Incident Response
If we learn of a security incident affecting our systems, we investigate, work to contain and remediate the issue, and assess what data may have been affected. Where a breach of personal information triggers a notification obligation, we will notify affected users and the appropriate regulators within the timeframes required by applicable law.
We do not operate an automated breach-notification system, and notification is not instantaneous. Investigation, verification, and notice are handled by our team, and the time required depends on the nature and scope of the incident.
8. Vulnerability Reporting
We welcome good-faith reports from security researchers and users. If you believe you have found a vulnerability in any of our services, please report it to [email protected] with enough detail for us to reproduce the issue.
- Give us a reasonable opportunity to investigate and remediate before any public disclosure
- Do not access, modify, or delete data belonging to other users, and do not degrade or disrupt our services
- Do not use social engineering, physical intrusion, or denial-of-service testing
- Use test accounts you control wherever possible, and stop testing as soon as you have confirmed a vulnerability
We do not currently operate a paid bug bounty program, and we cannot guarantee a reward for any report. We will acknowledge reports we receive and will make a good-faith effort to keep you informed of our progress.
9. Your Responsibilities
Account security is a shared responsibility. You should:
- Use a strong, unique password that you do not reuse elsewhere
- Never share your credentials or authentication tokens
- Sign out of shared or public devices
- Keep your browser, device operating system, and app updated
- Be cautious with links and attachments claiming to come from us, and verify the sender address before entering credentials
- Report suspected account compromise or suspicious activity promptly to [email protected]
10. No Guarantee of Absolute Security
No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect information using the measures described above, we cannot and do not guarantee that our services or the information you provide will be free from unauthorized access, loss, misuse, alteration, or destruction.
11. Related Policies
- Privacy Policy — what we collect, why, and who we share it with
- Data Deletion & Retention Policy — how to request deletion or export of your data
- Law Enforcement & Transparency Policy — how we handle subpoenas, warrants, and other government requests
- Terms of Service — the agreement governing your use of our services
12. Changes to This Policy
We may update this Security Policy as our systems and practices change. Material changes will be reflected in the "Last Updated" date shown at the top of this page. Continued use of our services after an update constitutes acceptance of the revised policy.
13. Contact
For security questions or vulnerability reports, contact our security team:
Security Inquiries
Security & Vulnerability Reports
Email: [email protected]
General Support: [email protected]
Mailing Address:
Grace Unworthy Ministries, LLC
5753 Highway 85 N PMB 3496
Crestview, FL 32536