General Availability
CEF Core reaches general availability with a production-hardened platform purpose-built for church extension fund financial management. This release represents the culmination of months of development, beta testing, and feedback from early-access customers.
New Features
- +Standalone Deployment on Hetzner Cloud -- Migrated from Firebase Cloud Functions to a dedicated Hetzner CPX31 instance with SSL via Let's Encrypt, providing lower latency and full infrastructure control.
- +JWT Authentication System -- Production-ready authentication with 24-hour access tokens, 7-day refresh tokens, and HS256 signing. Supports dual-mode authentication for backward compatibility with Firebase ID tokens.
- +Complete Loan Servicing Module -- End-to-end loan lifecycle management including origination, payment processing, amortization schedules, payoff calculations, and delinquency tracking.
- +Investor Note Tracking -- Full investor note management with interest accrual, maturity tracking, reinvestment handling, and automated 1099-INT generation.
- +Double-Entry General Ledger -- GAAP-compliant general ledger with chart of accounts, journal entries, trial balance, balance sheet, and profit-and-loss reporting.
- +CRM for Ministry Organizations -- Purpose-built CRM for managing church relationships, contacts, prospects, and organizational hierarchies.
- +Maker-Checker Workflow -- Four-eyes principle enforcement for all financial transactions exceeding configurable thresholds, with full approval audit trails.
- +Immutable Audit Trail -- Tamper-evident audit logging with cryptographic hash chains, ensuring regulatory compliance and forensic traceability for every financial operation.
- +Cash Management and Escrow Tracking -- Receipts, disbursements, reconciliation, and escrow account management with real-time balance tracking.
- +Report Builder with Highcharts -- Interactive report templates, custom report generation, PDF and Excel export, and visual dashboards powered by Highcharts.
Security and Compliance
- ~AES-256 encryption at rest for all financial data and TLS 1.3 for all data in transit.
- ~Role-based access control with admin, treasury, and staff tiers.
- ~Rate limiting with token bucket algorithm to prevent API abuse.
- ~Multi-factor authentication support for administrative accounts.
- ~Transaction limits with role-based thresholds and daily/monthly caps.
Infrastructure
- ~PostgreSQL 16 with 101 tables across 16 schemas, optimized for financial workloads.
- ~Redis 7 for session management, rate limiting, and caching.
- ~PM2 process management with automatic restarts and zero-downtime deployments.
- ~Automated disaster recovery with RPO of 1 hour and RTO of 4 hours.
- ~99.4% test pass rate across 162 automated tests (smoke and integration).