ChurchWork
← All posts

Comparing Church App Security: What to Ask Your Vendor

4 min read · Published August 4, 2026
Close-up of an adult in a blazer holding a clipboard with documents and a pen indoors.

Photo by Mikhail Nilov on Pexels

Before selecting a church engagement app, ask your vendor about five critical security practices: multi-factor authentication for admin accounts, role-based access controls, audit logging of all actions, a documented incident response plan, and independent security verification. These aren't optional. Without them, a compromised church app becomes a phishing weapon that impersonates your leaders to steal from members.

In July 2020, hackers broke into Twitter's internal systems and compromised the accounts of employees with administrative access. They didn't attack millions of users. They attacked the handful of people inside Twitter who could send messages from verified accounts. Once inside, they used those compromised credentials to post from Barack Obama's account, Bill Gates' account, Elon Musk's account, and dozens of others. From these trusted accounts with blue checkmarks, they posted a simple pitch: "We're giving back to the community. Send $1000 in Bitcoin and we'll send you $2000 back." Twitter documented this breach in detail; it was covered by every major news outlet. The reason it worked was simple. People saw an account they recognized and trusted the message. They had no way to know the account had been compromised by someone inside Twitter.

Now imagine that same attack against a church. A hacker compromises one admin account in your engagement app and sends a message to all 2000 members: "Click here to update your giving information" or "We're collecting emergency funds. Send mobile money to this number." Your members don't question it. It came from their pastor, or their worship leader, or a staff member they see every week. The link looks correct. The phone number looks correct. By the time anyone realizes it's fraudulent, hundreds have already clicked, entered information, or sent money.

That's what a poorly secured church app becomes: a phishing attack that weaponizes the trust you've built.

Questions About Data Access and Admin Controls

Start by asking your vendor: How many people at your company can see our member data? Under what conditions? Ask whether every action an admin takes is logged. Ask whether a single person can send a message to the entire congregation, or whether certain critical actions require approval from two administrators. Ask what happens when someone on your staff leaves the church. Does their access disappear the same day?

A credible vendor will have concrete answers. They'll explain role-based access controls (different people have different permissions based on their job). They'll describe audit trails (permanent records of who accessed what, when, and why). They'll talk about approval workflows (sensitive actions need multiple people to sign off). If a vendor says "we take security seriously" and stops there, keep talking to other vendors.

Ask about incident response. If they discovered a breach tomorrow, how would they detect it? How quickly would they notify your church? How would they communicate with your members? Vendors that haven't thought through this rarely give clear answers.

Protecting Admin Accounts

After access controls, focus on the strength of admin accounts themselves. Can admins use multi-factor authentication? This means a password plus a code from their phone or authenticator app. It slows attackers significantly, even if they steal a password. Some vendors make this optional. Better vendors make it mandatory.

Ask if the vendor supports single sign-on (SSO) through Google Workspace or Microsoft Entra. This means admins aren't creating weak church-specific passwords they reuse everywhere. It means the authentication work goes to companies that invest millions in security infrastructure.

Checking Vendor Track Record

Beyond technical setup: ask for real references. Not testimonials from their marketing page, but names of churches actually running the software. Call them. Ask if the vendor has ever had a security incident. How quickly did they fix it? Was the communication with churches clear and honest?

Look for signs of maturity. Does the vendor publish a public security policy? Have they undergone independent audits like penetration testing or SOC 2 certification? Is there a process for security researchers to report vulnerabilities? These aren't guarantees, but they signal real investment.

If your data will live in the cloud (most modern apps do), ask where servers are located, whether data is encrypted in transit and at rest, and whether the vendor complies with data protection regulations in your country.

You Remain Part of the Equation

Technical security is only half the story. Your team matters as much as the vendor's infrastructure. Train your admin team. Use strong, unique passwords. Don't share admin credentials via WhatsApp or email. Disable access immediately when someone leaves the church. Many church app breaches happen not because the app was broken, but because a staff member's personal phone was hacked and their church login was stored there.

Good vendors provide the tools and documentation to make security easy. You have to actually use them. Security is a partnership.

ChurchWork

A member engagement app for churches — events, giving, and groups that keep people connected between Sundays — backed by operations that have already run a real conference at roughly 8,752 registrations (bus coordination, registration, fund raising, disseminating announcements, publishing events etc.)

Try ChurchWork

Comments

No comments yet.