Built for the Executive Pastor who owns the risk

AI that knows your church, speaks in your tradition,
and keeps confidences.

Verolith is an AI-native operating system for the church, built on one shared AI-governance layer. Your staff work with an assistant grounded in your own sermons, minutes and confessional standards, and Aligned Chat checks every draft against your Codex — showing where it holds to your standard and where it drifts. Requests run through a governed gateway under enterprise no-training agreements; switch on the Privacy Airlock and names and pastoral detail are stripped before anything leaves. Opt into a provenance session and it closes with a tamper-evident record — a signed account of what informed the answer and how it was checked against your standard.

  • Grounded in your own sources
  • Airlock: fail-closed when on
  • Per-user audit trail
  • SSO + Directory Sync
  • Designed for SOC 2 Type II

The choice you don’t actually have

You can decline to use AI. You can’t stop AI from reaching your church.

A pastor can choose never to open a chatbot. What no pastor can choose is a world where AI isn’t already writing the devotional a volunteer pastes in, the study notes a member brings to group, the newsletter copy, the answers your congregation searches for on a Sunday afternoon. Abstaining doesn’t remove AI-generated content from your ministry —it only removes your standard from it.

Our answer isn’t “use more AI.” It’s governance: the tools to make sure the AI-shaped content moving through your church is grounded in your sources, checked against your confession, and traceable to what it came from. If AI content is unavoidable, alignment shouldn’t be optional.

§ 01 · Your corpus

Your own material

The settings that make AI actually useful

Generic chatbots make things up about your church because they’ve never read it. The corpus is the layer you control — what goes in, how often it refreshes, who can see it, and what gets stored. Everything the assistant says comes back grounded in that library, with the receipt attached.

  • Bring what you already have — point Verolith at a Drive, Dropbox, or Box folder, connect your church’s own video channel, or upload directly. Nobody re-uploads anything by hand each week.
  • Refreshes on your cadence — sync daily, weekly, or when something changes. Only what actually changed is re-read, and a broken connection surfaces to your admin instead of going quietly stale.
  • Video and paper become searchable — sermons are transcribed; scanned confessions and decades-old minutes are read page by page. Word, Excel, PDF, Pages and plain text all land in one searchable library.
  • Answers point at the moment — every result carries its source, so you can go to the passage it came from rather than taking the answer on faith.
  • Scoped to who should see it — each set carries its own access scope, so the finance file and the pastoral-care file are not equally reachable, and one church’s corpus is never visible to another.
  • Ingestion you can see — what is embedded, what needs re-embedding, what failed and why, per item. Bulk ingestion stays disabled until a retrieval quality check passes on your own material.

We don’t let you load ten thousand documents on day one. Bulk ingestion unlocks only after a retrieval quality check passes against your own corpus — because a library that returns the wrong passage confidently is worse than no library at all.

§ 02 · Aligned Chat

Aligned Chat

Useful isn’t enough. It has to hold to your standard.

Grounded answers stop the assistant inventing your church. They don’t make itorthodox. Aligned Chat checks claims against yourCodex — the confessional standards and statement of faith you load — and shows where a draft agrees, where it diverges, and where teaching has drifted.

This is what turns “AI wrote something” into“AI wrote something we can hold to our standard.”

  • Answers in your own pastor’s voice, grounded in your church’s sermon archive
  • Draft auditing against your confessional standard — Book of Concord, Westminster, your own statement of faith
  • Alignment and divergence, surfaced with citations — it doesn’t claim neutrality
  • Drift over time — where teaching on a doctrine has moved across ten years of sermons

§ 03 · Safe Chat

The Privacy Airlock

Switch it on, and nothing leaves that surface un-scrubbed

The Airlock is an optional scrubbing control — off by default — that you, or your organization’s policy, can switch on per surface. Enabled, it runs on our infrastructure in front of the model call: in three passes it removes what should never leave your walls — then lets a useful, fully reconstituted answer back in.

  1. 01

    Strips the obvious PII

    Names, emails, phone numbers, addresses, dates. The structural identifiers any compliance team expects to be removed — gone before the prompt leaves our gateway.

  2. 02

    Redacts the trauma generic tools miss

    Infidelity, abuse, addiction, a minor’s name, a family in crisis. Secular DLP was built to catch credit-card numbers; it is blind to the narrative pastoral detail that actually creates liability in a church. This is what we built for.

  3. 03

    Substitutes, then restores — locally

    Every sensitive span is swapped for a reversible placeholder, so the external model only ever sees “PERSON_1.” The real text is restored on our side, after the response returns — never in the prompt that egresses. The map that makes the swap reversible lives in a dedicated, isolated store — kept apart from every other church’s and from the billing ledger, and discarded shortly after the exchange.


If it’s on and can’t scrub, it doesn’t send.

An enabled Airlock is fail-closed. If any part of the scrubber errors or drops offline, the request is terminated on the spot — never forwarded un-scrubbed. When it’s on, it fails safe, not open. That single rule is the difference between a privacy promise and a privacy product.

§ 04 · Provenance

The risk you can’t see

Your staff are already pasting confidential situations into ChatGPT

A counseling conversation. A member’s marriage in crisis. A giving record. A minor’s name. Typed into a consumer AI tool that may retain it, train on it, or surface it later. You can’t un-send it — and today, you may never even know it happened.

Generic enterprise DLP was built to catch credit-card and Social-Security numbers. It is blind to the thing that actually creates liability in a church:the narrative of someone’s worst week, written in plain language.

Legal & insurance exposure

Counseling content and member data sent to a third party you never vetted — the kind of disclosure your liability carrier and your attorney would very much like to have been asked about first.

A breach of pastoral trust

People tell their church things they tell no one else. A confidence that leaks into a vendor’s training set isn’t a bug report — it’s a betrayal of the relationship your ministry runs on.

Reputational damage

One headline about a congregant’s private crisis surfacing from an AI tool undoes years of carefully built trust — and travels fast through exactly the peer networks you sell into.


Built for the risk owner

Everything the person who signs the contract needs to say yes

That’s the exposure. Here’s what you get to contain it. The Lead Pastor will love what it does — but you’re the one who has to defend it to the board, the insurer, and the IT director.

The AI work runs for you, not on your account

You don’t wire up a model vendor or hand a corporate card to an AI company. Inference and search are run on your behalf inside Verolith, and foundation-model traffic rides Google Cloud Vertex AI under our executed enterprise data-processing agreement, with retention-for-training contractually disabled — not a self-serve toggle, an executed contract.

A per-user audit trail

Who ran what, and when — never the content itself. The “who did what” record your access reviews, your board, and your insurer ask for.

Proof of how AI was used

When a staff member or student opts into a provenance session, every prompt and reply is captured as a tamper-evident, hash-chained record of exactly what egressed — scrubbed where the Airlock was on, raw where it wasn’t. They export a signed bundle a supervisor, grader, or board can verify independently. Admins see that a session happened; never what was in it.

Sign in with the identity you already have

Staff authenticate through your existing identity provider — Google Workspace, Okta, or Microsoft Entra — over single sign-on that’s live today. No new passwords, no shadow accounts, no tool sprawl for your IT director.

Access that follows your directory

Directory Sync provisions access from the groups you already manage. Add someone to the right group and they’re in; remove a departing staff member and their access goes with them — no separate user list to keep in step by hand.

Your church, isolated

Each church’s data lives in its own isolated tenant — never visible to another. Isolation scales from a shared schema to a dedicated database without changing how it works, and even the short-lived map that reverses the Airlock’s placeholders runs on its own isolated store.

Spend governance built in

A per-tenant budget ceiling means a runaway script or a compromised login can’t quietly drain your AI budget. Predictable cost is a first-class feature, not an afterthought.

Designed for SOC 2 Type II

Isolated data, no raw-prompt logging in our observability tooling, ZDR routing — architected to the standard from day one. Formal certification follows our first paid pilots; we won’t blur the line.

How it works

With the Airlock on, the model still does the work. It just never sees who it’s for.

The Airlock is opt-in, per user and per surface — here’s a request with it switched on. Like an airlock on a spacecraft, nothing moves between your people and the outside model without passing through a sealed, controlled chamber — in both directions.

  1. 1A staff member writesA prompt in the dashboard
  2. Our infrastructure2The Airlock scrubsPII + pastoral trauma removed; tokens substituted
  3. 3Vertex AI (Google Cloud DPA)Anonymized request to the model, retention-for-training off
  4. Our infrastructure4Reconstituted locallyPlaceholders restored on our side, after the reply
  5. 5The staff member readsA complete, useful answer

On an Airlock-on turn, the only text that crosses to the model is already anonymized. The mapping back to real names lives only on our side, in tenant-scoped storage, and expires on a short timer.

See it

This is the product, not a concept render.

Every screen below is the shipped dashboard. We build an integrity product, so the imagery holds to the same standard as the claims.

The Airlock, working

With the Airlock on, staff see the whole answer — the model never sees the person.

A pastoral question goes in as it was actually written — a name, a marriage coming apart, a son in treatment. With the Airlock switched on for this surface, the rail on the right counts what was stripped before anything egressed, and “view what egressed” shows the tokenized text the provider actually received. The reply comes back complete, reassembled on our side.

The Verolith chat surface. A staff prompt about a pastoral care visit sits above the assistant’s reply, while a right-hand panel reports three items removed before egress — one name and two family references — with the provenance ledger recording the turn.
FIG. 01The Airlock, working

Proof of how AI was used

A record a supervisor can verify without reading a word of it.

Inside an opt-in session, every prompt and reply is hash-chained to the one before it. A reviewer verifies the chain from the hashes alone — the content stays the member’s. Where the Airlock redacted a name, the ledger stores the placeholder — so on those scrubbed turns, even the record of the conversation holds no one’s details.

The Verolith provenance ledger showing a closed attestation session. A green banner reads “Chain intact — you’re covered”, and the entries display SHA-256 link hashes with a redacted __PERSON_1__ placeholder in the recorded prompt.
FIG. 02Proof of how AI was used

Your own material

Sermons, minutes, and policies — scoped to who should see them.

Sets of your church’s own source material, each with its own access scope, so the finance file and the pastoral-care file are not equally reachable. Ingestion state is visible per item: what is embedded, what needs re-embedding, what failed and why.

The Verolith corpus library showing seven content sets — sermon archive, media, confessions, governance, finance — with per-item ingestion status and a coverage overview panel.
FIG. 03Your own material

Spend governance

A budget ceiling, and a running tally of what the Airlock caught.

Advisory token budgets pace the month rather than cutting staff off mid-sentence. Alongside them, the session footprint reports what was removed before egress — including how many turns egressed raw text, the number an Airlock-on session keeps at zero.

The Verolith usage surface with monthly, weekly, and hourly advisory token meters, plus a session footprint reporting one prompt, one item of PII removed, two trauma indicators removed, and zero raw text egressed.
FIG. 04Spend governance

For your access reviews

Who did what, and when — never what they said.

A durable per-tenant record of activity, filterable and exportable to CSV for the access review your insurer or your board asks for. Identifiers and token counts only; the content of a prompt is never in this table, by design.

The Verolith audit log listing per-user activity rows with timestamps, action types such as chat.stream and rag.search, user names, roles, token counts, and request IDs.
FIG. 05For your access reviews

Screenshots are of the shipped product, captured against a demonstration tenant. “Grace Community Church,” its staff, and its documents are fictional — no real pastoral content appears in any image. Assistant replies shown are representative.

Precision over hype

We choose our words as carefully as we handle your data

You’re buying integrity. So we won’t sell it with claims we can’t stand behind. Here’s how we talk about the hard parts.

  • We won’t tell you “nothing is ever stored.” Foundation-model inference runs on Google Cloud Vertex AI under our executed data-processing agreement, with retention-for-training disabled.

  • Even then, “zero” isn’t literally zero. A provider may still retain a request that’s flagged for safety review, or where the law requires it. We say that out loud rather than burying it.

  • We’re designed for SOC 2 Type II — not yet certified. We’ll always tell you which is which, and show you exactly where we are in the process.

Pricing

Priced for the whole staff — not per seat

We count users so you can run access reviews, audit activity, and true-up at renewal. We never bill by them. Counting is what makes a flat license safe to operate — it’s free to you.

One flat license, keyed to your size

You pay a predictable enterprise fee based on your church — not a meter that climbs every time you add a staff member.

Your whole team, on purpose

Per-seat pricing tempts you to leave your most overworked junior staff off the platform — the exact people most likely to paste something they shouldn’t. So we don’t price that way.

You pay your own model usage

Token costs pass straight through at cost, governed by a budget ceiling you control. We don’t mark up the AI; we secure it.

Enterprise churches buy by PO and invoice. Tell us your size and we’ll scope a license.

Talk to us about a license

Questions a careful buyer asks

Straight answers

The hard ones, answered the way we’d want them answered if we were buying.

Does this mean nothing we send is ever stored?

No — and we won’t claim that. Foundation-model inference runs on Google Cloud Vertex AI under our executed data-processing agreement, with retention-for-training disabled. A provider may still retain a request that gets flagged for safety review, or where the law requires it. That’s the honest answer, and it’s still a dramatically smaller footprint than a staff member pasting into a consumer chatbot.

Do the AI providers train their models on our data?

No. The endpoints we route through have retention-for-training contractually disabled at the organization level. That contract is the foundation of the whole product.

How do our staff actually use it day to day?

In a private web app, reached through your church’s own single sign-on — nothing to install on anyone’s computer, no new account to create. Staff sign in with your existing identity provider — Google Workspace, Okta, or Microsoft Entra — using the login they already have, so there’s nothing new to remember. Every request is routed through the governed gateway before any external model sees it — and the optional Privacy Airlock, off by default, can be switched on per surface to scrub prompts on the way out. Directory Sync provisions access from the groups you already manage and removes it when someone leaves, so IT doesn’t maintain a second user list.

What about our own sermons and member records?

Your tenant’s data is isolated to your church and never visible to another. Every request — including one grounded in your own sermons or records — still runs on the same Google Cloud Vertex AI rail under our data-processing agreement, with retention-for-training disabled, as any other traffic; and when the Airlock is on, that content passes through the same scrubbing as a typed prompt before anything egresses.

Will our own staff still see our own people’s names?

The scrubbing — when you switch it on — happens on the way out to the model; that’s what makes it an airlock rather than a censor on your own filing cabinet. Your church’s records stay your church’s records, and what leaves an Airlock-on turn is de-identified.

Do we have to let our staff use AI at all?

No — and that’s rather the point. Whether or not your staff ever open it, AI-shaped content is already reaching your church: in the devotional a volunteer pastes in, the study notes a member brings to group, the answers your congregation searches for. Abstaining doesn’t remove that content; it only removes your standard from it. Verolith is how you hold it to one.

Can our staff prove how they used AI — for a grader, a board, or a policy?

Yes. A staff member or student can work inside an opt-in provenance session: every prompt and AI response is captured as a tamper-evident, hash-chained record (the exact text that egressed — scrubbed where the Airlock was on), and they export a signed attestation bundle anyone can verify independently. It’s an honest record of AI use through the platform — it can’t prove what someone did in another tab, and we don’t claim it does. Admins see that a session happened, never its contents.

Are you SOC 2 certified?

We are designed for SOC 2 Type II from day one — isolated data, no raw-prompt logging in our observability tooling, ZDR routing. Formal certification follows our first paid pilots. We won’t blur the line between “designed for” and “certified,” and we’ll show you exactly where we are.

Who decides the standard our content is checked against?

You do. You load your own confessional standards and statement of faith as your Codex — Book of Concord, Westminster, your own statement — and Aligned Chat checks drafts against it, showing where they agree, where they diverge, and where teaching has drifted over the years. It doesn’t claim neutrality, and it shows its work with citations.

Get the conversation started

See it against your own church’s risk profile

We’ll walk you and your IT director through the Airlock, the audit trail, and exactly where we are on compliance — no overclaiming, no pressure.