When a family joins your church, they hand you more than their attendance. They give you their kids' names and allergies, their home address, their giving history, sometimes a note about a marriage that is struggling or a job that was lost. That information lives in your church management software now. Which means the question is not really "is this software easy to use?" It is "can I trust it with the people who trusted me?"
That is a pastoral question dressed up as a technical one. And most of us were never trained to ask it well.
Data security is not an IT problem you delegate. It is a form of care. Protecting a congregation's information is part of protecting the congregation.
The good news is you do not need to become a security engineer. You need a short list of the right questions and the confidence to ask them out loud before you sign a contract. Here is that list, written for pastors and administrators — not for a server room.
The ground has shifted under every organization that handles payments and personal data, churches included. A few realities worth knowing:
The payment-security standard known as PCI DSS moved to version 4.0, with the full set of requirements becoming mandatory as of March 31, 2025 — and many nonprofits still are not fully compliant. At the same time, comprehensive state privacy laws are now active or taking effect in at least 20 states, and while many still exempt religious organizations outright, that exemption is narrowing. The organizations that moved early are in the best position now.
None of this should make you anxious. It should make you specific. The vendors who take security seriously will have clean, confident answers to the questions below. The ones who do not will get vague — and vagueness is your answer.
Any platform that touches giving must meet the Payment Card Industry Data Security Standard. Ask for the current version (4.0 is the baseline now) and how they handle card data. The best answer is that card numbers never touch the church's systems at all, because payments are processed through a certified provider. If you hear hesitation here, stop.
SOC 2 Type II is the closest thing to an independent seal of trust in this space. It means an outside auditor tested the vendor's security controls over a sustained period, not just on a single day. Security experts increasingly treat it as the minimum bar for any vendor holding sensitive data. Ask whether they have it, or where they are in the process of getting it.
Not everyone who volunteers should see everyone's giving records. A strong platform gives you granular roles — so a check-in volunteer sees rosters but not finances, and a group leader sees their group but not the whole directory. Ask to see the permission model. If everyone with a login can see everything, that is a red flag for a church of any size.
Ask how authentication works and whether it supports modern protections like single sign-on and multi-factor authentication. Passwords alone are not enough anymore. You want a platform that makes strong login the default, not an advanced setting nobody turns on.
Your congregation's data should be yours. Ask whether you can export it, what happens to it if you leave, and how it is protected in transit and at rest. A confident vendor will tell you plainly that the data belongs to the church and can be exported on request.
This is the newest question and the one most vendors are not ready for. If a platform uses AI — for content, summaries, or assistance — ask what data the AI sees, whether member information is used to train outside models, and whether you can turn AI features off. "We use AI" is not an answer. "Here is exactly what it touches and what it does not" is.
Even excellent systems have incidents. Ask what their breach-notification process looks like and how quickly you would be told. A vendor who has thought about the bad day is a vendor who is less likely to have one.
| Ask about | Green flag | Red flag |
|---|---|---|
| Payments | PCI DSS 4.0; card data never touches church systems | "We're basically compliant" |
| Independent audit | SOC 2 Type II report available | No audit, no timeline |
| Access control | Granular, role-based permissions | Everyone sees everything |
| Login | SSO + multi-factor supported | Passwords only |
| Your data | Exportable; owned by the church | Locked in, unclear ownership |
| AI | Clear, opt-out, no training on member data | Vague hand-waving |
We built EvangelOS around the assumption that a pastor should be able to ask these questions and get straight answers. Payments run through Stripe Connect, so card data is handled by a PCI-certified processor rather than sitting in your church's system. Logins are managed through an enterprise identity provider with support for single sign-on and multi-factor authentication. Permissions are role-based, so a check-in volunteer and a finance team member see very different things. And where AI assists — drafting a communication, summarizing an update — it is a helper working inside your data, not a doorway sending it somewhere else.
We say that not to close the conversation but to model it. Whatever platform you choose, make it earn your trust out loud. Your congregation handed you their information as an act of faith. Asking hard questions of the software that holds it is one of the quietest, most important ways you honor that.
Sources: StratusLive — Nonprofit Donor Data Security: Complete Guide 2026; The Nonprofit Alliance — PCI 4.0 Is Coming; SecureGive — Security Questions to Ask Your Giving Provider.