ChurchDesk ApS
Denmark · owned by Independent (Denmark) · www.churchdesk.com · 17 vendors
Resilience scores
- Digital Sovereignty: 47
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Combell Group — Technology — Belgium
- Cookiebot (Cybot A/S) — Technology — Denmark
- HubSpot, Inc. — Technology — United States
- and 14 more
Services catalogue
1 service in catalogue across 1 category; runs on 17 sub-vendors.
- ChurchDesk
Insights
Last updated 2026-09-13 · revision 1
17 direct vendors, 201 subvendors
Direct vendors by controlling owner country (sample)
- United States: 4
- Romania: 1
- Israel: 1
Subvendors by controlling owner country (sample)
- Switzerland: 1
- Australia: 1
- Denmark: 4
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ChurchDesk ApS exhibits good migration readiness, primarily due to its existing cloud-native architecture and SaaS operational model. The company already utilizes Amazon Web Services (AWS) and Heroku, indicating a significant head start in cloud adoption. The internal tech stack, featuring Ruby on Rails and AngularJS, combined with key technologies like RESTful API, Multi-tenancy Architecture, and Mobile Application Development, suggests a modular and adaptable system that would facilitate migration efforts. The absence of specified data residency requirements simplifies potential moves, as there are no explicit geographical constraints on data storage. Furthermore, the use of standard integrations like Stripe, Twilio, and SendGrid suggests a component-based approach that can be more easily re-integrated or swapped during migration. However, there are areas of uncertainty that could pose challenges. The regulatory environment is not specified, meaning potential compliance requirements for data handling or operations during migration are unknown. Similarly, financial stability data (revenue concentration, growth history) is missing, which is crucial for assessing the company's ability to fund a significant migration project. The vendor lock-in risk is also unknown; while the geographic diversity of vendors is high, the level of dependency on core platforms like Heroku or AWS could influence the complexity and cost of migrating away or to different services.
Compliance
5 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
ChurchDesk ApS is headquartered in Denmark (EU member state) and operates a church management SaaS platform that explicitly processes highly sensitive personal data — including religious beliefs/affiliation (a special category under GDPR Article 9), member databases, newsletters, contact information, and internal communications for churches across multiple countries. As a data processor and likely data controller, ChurchDesk faces elevated GDPR obligations. Non-compliance can result in fines up to €20 million or 4% of global annual turnover. The processing of special category data (religious affiliation) significantly elevates the risk profile. Danish DPA (Datatilsynet) is an active enforcement authority. The risk is High due to the sensitivity of data processed and the multi-country nature of operations.
Evidence: https://www.churchdesk.com/, https://www.datatilsynet.dk/english, https://gdpr-info.eu/art-9-gdpr/
SOC 2 (source) — Assessment Required
ChurchDesk is a cloud-based SaaS provider storing sensitive church member data, financial records, and communications. Enterprise and institutional customers (churches, dioceses) increasingly require SOC 2 Type II reports as part of vendor due diligence. Without a SOC 2 report, ChurchDesk may face procurement barriers with larger church organizations or dioceses. The risk is Medium because: (1) SOC 2 is not legally mandated but is a strong market expectation for SaaS providers; (2) the absence of a SOC 2 report creates reputational and commercial risk; (3) the company processes sensitive religious and personal data making security assurance important.
Evidence: https://www.churchdesk.com/, https://www.aicpa-cima.com/resources/landing/soc-2
ISO 27001 (source) — Assessment Required
ISO 27001 certification is increasingly expected of SaaS providers handling sensitive personal data. ChurchDesk processes religious affiliation data (GDPR special category), member databases, financial information, and internal church communications. The absence of ISO 27001 certification creates risk in enterprise sales cycles and may be a gap in demonstrating GDPR compliance (security of processing, Art. 32). Risk is Medium because ISO 27001 is voluntary but strongly recommended for SaaS companies of this profile, and its absence may indicate immature information security governance.
Evidence: https://www.iso.org/isoiec-27001-information-security.html, https://www.churchdesk.com/
Financials
Three-year financials
- 2025: gross profit DKK 24.6M, EBIT DKK 4.52M, equity DKK 19.3M
- 2024: gross profit DKK 14.4M, EBIT DKK -3.62M, equity DKK 14.0M
- 2023: gross profit DKK 14.1M, EBIT DKK -636K, equity DKK -11.9M
Financial Resilience Score: 6/10
ChurchDesk ApS operates a recurring SaaS revenue model in a vertical niche (church management software), which typically provides stable, predictable cash flows with low customer churn. Church customers rely on the platform for mission-critical operations including calendar/booking, CRM, communications, and website management, creating high switching costs and revenue stickiness. The company has diversified geographically across Denmark, UK, and Germany, reducing single-market concentration risk. However, actual financial statements (revenue, EBIT, equity) could not be retrieved from Danish CVR filings during this research, limiting the ability to assess balance sheet strength, profitability trends, or liquidity. As a small Danish ApS, ChurchDesk faces scale limitations, restricted capital access, and operates in a small addressable market (churches with limited budgets). Competition from ChurchSuite, Planning Center, and generic productivity tools (Microsoft 365, Google Workspace) presents ongoing pressure. The score reflects qualitative business model strengths offset by unknown financial specifics and small-company risk factors.
Key strengths: Recurring SaaS revenue model with low churn, Sticky vertical niche with defensible market position, International expansion across Denmark, UK, and Germany, Bundled offering replacing multiple SaaS tools increases wallet share, Mission-critical software for church operations creates high switching costs
Risk factors: Small addressable market with limited church budgets, Potential concentration on Danish state church (folkekirken) parishes, Small-company scale risk with limited capital access as private ApS, Competition from ChurchSuite (UK), Planning Center (US), and generic tools, Central IT procurement changes could materially impact revenue
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.