Features
Managed ServicesPricingContact
Back to blog

The Security Questions Every Pastor Should Ask Before Trusting Software With Their Church

When a family joins your church, they hand you more than their attendance. They give you their kids' names and allergies, their home address, their giving history, sometimes a note about a marriage that is struggling or a job that was lost. That information lives in your church management software now. Which means the question is not really "is this software easy to use?" It is "can I trust it with the people who trusted me?"

That is a pastoral question dressed up as a technical one. And most of us were never trained to ask it well.

Data security is not an IT problem you delegate. It is a form of care. Protecting a congregation's information is part of protecting the congregation.

The good news is you do not need to become a security engineer. You need a short list of the right questions and the confidence to ask them out loud before you sign a contract. Here is that list, written for pastors and administrators — not for a server room.

Why this matters more in 2026

The ground has shifted under every organization that handles payments and personal data, churches included. A few realities worth knowing:

The payment-security standard known as PCI DSS moved to version 4.0, with the full set of requirements becoming mandatory as of March 31, 2025 — and many nonprofits still are not fully compliant. At the same time, comprehensive state privacy laws are now active or taking effect in at least 20 states, and while many still exempt religious organizations outright, that exemption is narrowing. The organizations that moved early are in the best position now.

None of this should make you anxious. It should make you specific. The vendors who take security seriously will have clean, confident answers to the questions below. The ones who do not will get vague — and vagueness is your answer.

The seven questions

1. Are you PCI DSS compliant — and to which version?

Any platform that touches giving must meet the Payment Card Industry Data Security Standard. Ask for the current version (4.0 is the baseline now) and how they handle card data. The best answer is that card numbers never touch the church's systems at all, because payments are processed through a certified provider. If you hear hesitation here, stop.

2. Do you hold a SOC 2 Type II report?

SOC 2 Type II is the closest thing to an independent seal of trust in this space. It means an outside auditor tested the vendor's security controls over a sustained period, not just on a single day. Security experts increasingly treat it as the minimum bar for any vendor holding sensitive data. Ask whether they have it, or where they are in the process of getting it.

3. Who can see what — and can you control it?

Not everyone who volunteers should see everyone's giving records. A strong platform gives you granular roles — so a check-in volunteer sees rosters but not finances, and a group leader sees their group but not the whole directory. Ask to see the permission model. If everyone with a login can see everything, that is a red flag for a church of any size.

4. How do people log in, and is it protected?

Ask how authentication works and whether it supports modern protections like single sign-on and multi-factor authentication. Passwords alone are not enough anymore. You want a platform that makes strong login the default, not an advanced setting nobody turns on.

5. Where does my data live, and can I get it back?

Your congregation's data should be yours. Ask whether you can export it, what happens to it if you leave, and how it is protected in transit and at rest. A confident vendor will tell you plainly that the data belongs to the church and can be exported on request.

6. What is your AI policy?

This is the newest question and the one most vendors are not ready for. If a platform uses AI — for content, summaries, or assistance — ask what data the AI sees, whether member information is used to train outside models, and whether you can turn AI features off. "We use AI" is not an answer. "Here is exactly what it touches and what it does not" is.

7. What happens when something goes wrong?

Even excellent systems have incidents. Ask what their breach-notification process looks like and how quickly you would be told. A vendor who has thought about the bad day is a vendor who is less likely to have one.

A quick scorecard

Ask aboutGreen flagRed flag
PaymentsPCI DSS 4.0; card data never touches church systems"We're basically compliant"
Independent auditSOC 2 Type II report availableNo audit, no timeline
Access controlGranular, role-based permissionsEveryone sees everything
LoginSSO + multi-factor supportedPasswords only
Your dataExportable; owned by the churchLocked in, unclear ownership
AIClear, opt-out, no training on member dataVague hand-waving

What good looks like

We built EvangelOS around the assumption that a pastor should be able to ask these questions and get straight answers. Payments run through Stripe Connect, so card data is handled by a PCI-certified processor rather than sitting in your church's system. Logins are managed through an enterprise identity provider with support for single sign-on and multi-factor authentication. Permissions are role-based, so a check-in volunteer and a finance team member see very different things. And where AI assists — drafting a communication, summarizing an update — it is a helper working inside your data, not a doorway sending it somewhere else.

We say that not to close the conversation but to model it. Whatever platform you choose, make it earn your trust out loud. Your congregation handed you their information as an act of faith. Asking hard questions of the software that holds it is one of the quietest, most important ways you honor that.

Ask us the seven questions →


Sources: StratusLive — Nonprofit Donor Data Security: Complete Guide 2026; The Nonprofit Alliance — PCI 4.0 Is Coming; SecureGive — Security Questions to Ask Your Giving Provider.