Your church’s data, protected at every layer.
Encrypted in transit and at rest, running on infrastructure built to stay up, and yours to export or delete whenever you decide. Here is which standard applies where.
Encrypted, both ways
HTTPS/TLS on everything in transit, and AES-256 encryption on everything at rest.
Built to stay up
Managed, replicated infrastructure with no servers of our own to fall over. Durability and failover are handled at the platform level.
Your data, yours to take
You keep full control of your church’s records and can export what you need, whenever you need it. Nothing is held hostage.
Twenty areas, four levels
Give someone exactly what their ministry needs and nothing else. Settings and billing can never be granted through a role.
Passwords never reach us
Sign-in is handled by a managed authentication service. Churchory never receives, stores, or can read a password.
Leaving is a button
Delete your account and church data yourself from settings, or email us and it’s gone within 30 days.
Which standard applies where.
Encryption isn’t one setting. It’s a different mechanism at each layer, and the useful question is which one is protecting what.
| Layer | Standard | How it’s applied |
|---|---|---|
| Data in transit | HTTPS / TLS | Every connection — the web app, the mobile apps, and the APIs between them. There is no unencrypted path into Churchory. |
| Data at rest | AES-256 | Applied to every stored record and uploaded file, with managed key handling. |
| Passwords | Never stored by us | Sign-in runs on a managed authentication service. Churchory never receives, stores, or can read a password. |
| Card numbers | PCI DSS Level 1 | Entered directly into Stripe, a Level 1 service provider, and never transmitted to or stored on a Churchory server or database. |
| Isolation between churches | Enforced beneath the app | Security rules the database platform evaluates on every read and write — underneath our code rather than inside it, so a bug in the app can’t talk its way past them. |
| Availability | Managed & replicated | Your records sit in a managed, replicated database. Durability and failover are the platform’s job, not a nightly script of ours. |
| Underlying platform | ISO/IEC 27001 · SOC 1, 2, 3 · PCI DSS | Held by our infrastructure provider, covering the physical, hardware, and network layers beneath us. These are the provider’s certifications, not ours — we don’t present them as ours. |
The two things we deliberately can’t decrypt
Your members’ passwords and your donors’ card numbers never reach us in any form. That isn’t a policy we promise to keep — it’s an architecture in which we have nothing to leak.
Found something? Tell us.
Email [email protected] with “Security” in the subject line. We’ll acknowledge it, we’ll fix it, and we will never pursue legal action against anyone reporting a vulnerability in good faith.