Home / Products / PCC Documents

PCC Documents

Every document your PCC must publish, kept in order and checked for viruses.

A secure, simple website service for Parochial Church Councils. The public find what a PCC is expected to publish. Members see the private papers. Volunteers upload from a phone or an old laptop, and every file is virus-checked before anyone can open it.

Documents go out of date quietly.

A PCC is expected to make a long list of documents available: the accounts and annual report, the safeguarding policy, the privacy notice, the table of fees, public minutes. Other papers, such as the fire risk assessment and full minutes, must stay private to the PCC.

In practice they live in email attachments, a shared drive and someone's memory. Review dates slip, the wrong version gets sent round, and the worst mistake, a private document published by an honest volunteer, is always one click away.

Out of date, unnoticed

Nothing says a policy was due for review last spring.

The wrong people see it

Full minutes or an electoral roll with addresses ends up somewhere public.

Files nobody has checked

Attachments are opened on home computers with no check at all.

Leavers keep access

Someone steps down, but their copies and their logins don't go away.

Security first

Nothing can be opened until it has been checked.

Members open these files on their own computers. So every file goes through two independent layers of checking before it is available to anyone, including the person who uploaded it.

  1. The file itself is inspected

    It must really be a PDF, Word or Excel file, whatever its name says. Files that can run code, open other files or hide their contents are refused with a plain explanation.

  2. Then it's virus-scanned

    Every upload is scanned with ClamAV, a widely used open-source virus scanner. Until the scan finishes the file cannot be opened by anyone, and it appears in no page, list or email.

  3. Clean means live

    A clean file is published at once. An infected file is rejected, and the uploader is told in plain words.

  4. Checked again as definitions update

    Published files are re-scanned when the virus definitions move on, so a file that was clean last month is checked against what is known today.

The scanner is treated as untrusted.

It runs in its own isolated container with no access to your data or credentials and no internet beyond fetching virus-definition updates. Even if a crafted file could trick a scanner, there is nothing for it to take, and it can only ever mark a file clean or rejected.

An honest note on what a virus scan can do.

Virus scanning recognises known malware. It will not catch something brand new or aimed at one target, which is why the structural checks come first and why nothing here claims to be unbreakable. It is a second, independent layer, and good diligence.

Files that can do harm are refused, not just scanned.

The structural checks catch things a virus scanner is not designed to judge.

Dangerous PDFs

PDFs containing JavaScript, launch actions, embedded files, rich media or forms that submit data are refused. So are encrypted PDFs and ones built to overwhelm the checker.

Macros and risky fields

Macro-enabled Word and Excel files are refused, along with files containing fields or formulas that run programs or pull in other files.

Hidden content in Word and Excel

Tracked changes, comments, hidden text and hidden sheets are detected. The file is held until someone has looked and chosen to publish it.

Confidential wording in a public file

A public document that mentions "confidential", "Part B" or "in camera" is held for a person to look at before it goes out.

Size and rate limits

Files are limited to 20 MB and uploads are rate-limited, so a mistake or a misbehaving program can't flood the service.

Only the right file types

PDF, Word (.docx) and Excel (.xlsx), decided from the file's own bytes, never from its name or what the browser claims.

Privacy by design

The type of document decides who can see it.

The most likely real incident is a volunteer publishing something private. So wherever the law already fixes the answer, the service removes the choice instead of warning about it.

Accounts, the safeguarding policy and the table of fees can only be public. The fire risk assessment, asbestos register, full minutes and the full electoral roll can only be members-only. For anything else, an uploader can only make a document more private, never less.

Never online at all

Keyholder and alarm codes, bank details, safeguarding case files and DBS details, and historical registers are on a forbidden list. The service won't accept them.

Members-only means members-only

Anyone else, signed in or not, gets a plain "not found". It doesn't even confirm the file exists. Members-only files are never stored by browsers or shared caches.

One PCC can't see another's

Each PCC's private documents are visible only to its own members. Isolation between different benefices is enforced in one place in the code and guarded by tests.

Clear on the page

Members-only documents carry a padlock and the words "PCC members only", so nobody has to guess.

No passwords to leak, and access that ends when it should.

Four roles, each able to do only what it needs.

Sign in with an emailed link

Each link works once and expires, so there is no password to forget, reuse or have stolen.

Passkeys for the sensitive moments

A fingerprint or face check on the person's own phone or computer, nothing to type. It is asked for before the most sensitive actions, such as permanently deleting a document or changing who has access.

Public, member, editor, manager

Members read. Editors upload, replace and archive. Managers add and remove people. A vicar who serves several churches is added once and given the right role in each.

Removal takes effect at once

Membership is checked on every request, so taking someone off a PCC ends their access straight away.

A record of who did what

Uploads, publications, downloads of members-only files and changes to access are all recorded in an audit log, kept without storing people's names in it.

A record of every email sent

When someone says they never got a sign-in link, there is an answer, not a guess.

Everything a PCC needs to look after its documents.

Built around the real life of a parish: a handful of volunteers, an annual meeting, and a list of documents that never quite stays up to date.

Knows what you should publish

A built-in list of the documents a PCC is expected to keep, each with the reasoning behind it, so you aren't working from memory.

A public site for every church

One home page for the benefice and a page for each church. Documents are found in one or two taps, and the safeguarding contact is always easy to find.

A private members' area

Members see everything the public sees, plus the PCC's private papers, in one place.

Status in plain words

"Up to date", "Needs checking by 1 August", "Overdue since 1 August", or "Not uploaded yet", shown beside each document. Gaps are visible, not hidden.

A To do page and a countdown

What is overdue, what is due in the next 60 days and what is missing, most urgent first, with a countdown to the annual meeting (APCM). Each item has a one-tap Upload, Replace, or "Checked, no changes needed".

Email reminders

A nudge before something is overdue, not after. Everything due that day arrives in one email per person, not a stream of them.

Simple uploading

Drag and drop or choose a file, from a phone or an old laptop. The form works without JavaScript, and tells you who will be able to see the document before you press the button.

PDF, Word and Excel

Upload the file you already have. The checks above apply to every one of them.

Drafts before they're final

Put a draft beside the current version for the PCC to review. Nobody sees it until you publish.

Every version kept

Replace a document and the earlier version stays on record. Minutes, notices and other running records are added to, never overwritten.

Shared documents, separate adoption

Upload a benefice-wide policy once. Each PCC still records its own adoption date, as the law expects, and the page shows who hasn't yet.

Update emails, your way

Members choose straight away, a daily round-up, a weekly round-up, or never. Emails contain links, never attachments, so a private document never travels by email.

Data protection built in

The housekeeping you would otherwise forget.

A PCC is the data controller for its members' details. The service does the routine parts of looking after that data, so it isn't left to whoever remembers.

It helps a PCC meet its duties. It is not legal advice, and it doesn't replace taking advice where you need it.

Archive, never delete

Nothing an editor does deletes a document. Archiving hides it and keeps every file, and it can be restored at any time.

Deliberate permanent deletion

Only a manager can delete something already archived, with a reason, a typed confirmation and a passkey check. A benefice-wide document also needs a second manager to approve.

Old records cleared out

A daily clear-out removes expired sign-in links, old sessions, and old email records on a fixed schedule. Earlier versions of documents go when their retention period ends.

Erase a person

A manager can remove someone and their records in one all-or-nothing step, and a restored backup cannot bring them back.

Nightly backups

Every night the whole database is backed up to separate storage and older copies are cleared out after 35 days.

Held in Cloudflare's EU region

Documents and records are stored on Cloudflare, with data and files in its EU region, and the virus scanner sends nothing to any third-party scanning service.

What it gives your PCC.

Confidence you've published what you should

The gaps are on the page, with the date each document was last checked.

Fewer honest mistakes

The service removes the risky choices instead of relying on everyone getting every decision right.

Safer than attachments and shared drives

Access is by role and checked every time, files are scanned, and private papers are shared by link behind a sign-in, not by email.

A lighter load for volunteers

Reminders do the remembering, and the To do page says what to do next.

One place for the whole benefice

Several churches and several PCCs on one site, each with its own page and its own private papers, and clergy entered once.

Easy for the least technical member

Plain wording, no passwords, and a plain-English help guide for whoever looks after it.

Accessible

Every page is checked automatically for accessibility problems on desktop and phone before it is released.

An answer when something goes wrong

An audit log and an email log mean "who changed that?" and "did the email go?" can be answered.

Run for you

We set up your site and look after the platform, including the scanner and its updates, so you don't need technical people in the PCC.

Built the way we build everything.

PCC Documents was specified feature by feature before any code was written, with numbered acceptance criteria that the automated tests check. Its design went to an independent security review first, and security is checked again before each release by someone other than the person who built the change.

It is being set up first for the Kington Parishes benefice (five churches, five PCCs), whose website we also built.

Ready to talk?

Tell us how many churches and PCCs you have and what you keep today, and we'll show you how it would work for you. Our approach to cost is on the prices page.