Security & trust

Stewardship of data is stewardship of people.

A church database holds stories people trusted you with. This page says, specifically, how we protect them. No badges, no vague reassurance: just the actual behavior of the platform, in plain language.

Protection

How your data is protected.

01

Encrypted, both directions

Everything is encrypted in transit and at rest. There is no plain-HTTP path to your data, and backups are encrypted before they ever leave the server.
02

Every church, strictly separate

Each church's data is isolated per workspace, and the isolation is enforced by the database engine itself through row-level security, not just by application code. A query from one church physically cannot see another church's rows.
03

Permissions per person

Pastors see giving totals. Finance sees details. Volunteers see only what they need. Every role is configurable per person, and administrative actions are audit-logged.
04

Abuse kept out

Sign-in and signup are protected by rate limits and automated bot checks, and every account action leaves a trail.
Continuity

Backups that are actually tested.

  • Backed up nightly, every night, automatically.
  • Encrypted before leaving the server, then stored off-site in a separate location from production.
  • Multiple restore points retained: daily, weekly and monthly generations.
  • Backup integrity is verified on a weekly schedule, not assumed.
  • Monitoring alerts us if a backup run is ever missed, and documented restore procedures exist for the day we hope never comes.
POPIA & residency

POPIA-first, and close to home.

We operate POPIA-first: your congregation's information is processed only to run your workspace, and you can export or delete it at any time.

Under POPIA, your church remains the responsible party for its congregation's personal information, and Church Flow acts as an operator: we process it on your instructions, to provide the service, and for nothing else. We do not sell, mine or advertise against your data.

Your data is hosted in a cloud data centre in South Africa, so it stays under the same sky as your congregation.

No hostage-taking

What happens if you leave.

Your church owns its data, full stop. Export your people, giving and attendance any time. If you cancel, you keep access until the end of your paid period, take everything with you, and we purge our copy after the 90-day retention window. No lock-in, no hostage-taking.

What we do not claim

No certification theater.

We do not hold SOC 2 or ISO 27001 certification, and we will not imply otherwise with borrowed badges. Almost nobody serving churches at this price point does. What you get instead is this page: specific, verifiable behavior, kept current. Found something that worries you? Write to us and a real person will answer.

Questions before you commit?

Ask them. Boards and finance teams welcome.

Talk to a real person

Read the switching guide · See pricing