ChurchSuite
United Kingdom · churchsuite.com · 19 vendors
Resilience scores
- Digital Sovereignty: 5
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- AbuseIPDB — Cybersecurity — United States
- Mandrill (an Intuit company) — United States
- Meta Platforms, Inc. — Technology — United States
- and 16 more
Services catalogue
1 service in catalogue across 1 category; runs on 19 sub-vendors.
- Donations
Insights
Last updated 2026-07-01 · revision 2
19 direct vendors, 261 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- Australia: 1
- United States: 16
Subvendors by controlling owner country (sample)
- United States: 192
- Romania: 2
- Sweden: 6
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ChurchSuite exhibits high migration readiness, primarily due to its existing cloud-native and multi-cloud infrastructure across Amazon Web Services (AWS), Google Cloud Platform, and Digital Ocean. This indicates a mature cloud adoption strategy and significant flexibility for migrating or re-platforming services. The use of a RESTful web application architecture and automated testing (CI) further streamlines potential migration efforts. Per-account database segregation also simplifies data migration processes. The company's diverse vendor ecosystem for critical services (e.g., Ably, Twilio, Mailgun, Stripe) suggests a lower risk of vendor lock-in compared to relying on a single, integrated platform, allowing for easier component swapping or re-integration during a migration. While the specific details on data residency requirements and the broader regulatory environment (beyond GDPR compliance) are not provided, and explicit vendor lock-in risk is unknown, the current technological foundation strongly positions ChurchSuite for efficient and effective migrations.
Compliance
8 in-scope frameworks identified; showing 3.
Australian Privacy Act 1988 — Assessment Required
ChurchSuite explicitly operates an Australian site variant (au.churchsuite.com), indicating active operations and customer acquisition in Australia. The Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) apply to organisations with annual turnover exceeding AUD $3 million, or to organisations that handle health information or certain other sensitive data. Churches using ChurchSuite in Australia would be Data Controllers, and ChurchSuite would be a service provider processing personal data on their behalf. The risk is Medium because: (1) ChurchSuite clearly has Australian operations, (2) the Privacy Act obligations for service providers handling Australian personal data are significant, (3) no Australian-specific privacy compliance documentation was found, (4) the 2022 Privacy Act Review recommendations (if enacted) would significantly expand obligations.
Evidence: https://churchsuite.com/
SOC 2 (source) — Assessment Required
ChurchSuite is a cloud SaaS provider processing sensitive personal data (church membership, children's data, financial/donation records) for thousands of organisations. SOC 2 is highly relevant for cloud service providers and is increasingly expected by enterprise customers and data protection-conscious organisations. No SOC 2 Type I or Type II report was found in public sources. The risk is Medium because: (1) absence of SOC 2 certification is a gap for a cloud SaaS provider handling sensitive data, (2) larger church customers or those with formal governance requirements may require SOC 2 evidence, (3) however, ChurchSuite's primary customer base (churches) may not typically demand SOC 2, reducing immediate commercial risk. The company does conduct annual CREST-approved penetration testing, which partially addresses security assurance needs.
Evidence: https://churchsuite.com/security, https://churchsuite.com/gdpr
UK Children's Code — Assessment Required
ChurchSuite explicitly provides a children's ministry module with 'secure check-in for children and visitors' and processes children's personal data. The UK Children's Code (ICO's Age Appropriate Design Code) applies to online services likely to be accessed by children under 18. While ChurchSuite is a B2B platform (churches are the customers, not children directly), the platform processes children's data on behalf of churches and includes child-facing or child-data-processing features. Risk is High because: (1) children's data is among the most sensitive categories under UK GDPR, (2) the ICO has been actively enforcing the Children's Code, (3) any gaps in how children's data is handled (consent, data minimisation, retention) could result in significant regulatory action, (4) the platform explicitly markets children's ministry features including check-in systems.
Evidence: https://churchsuite.com/, https://churchsuite.com/gdpr, https://churchsuite.com/tour/children
Financials
Three-year financials
- null:
Financial Resilience Score: 7/10
ChurchSuite Ltd demonstrates strong qualitative financial resilience despite the absence of publicly disclosed financial figures due to UK small-company filing exemptions. The company operates a recurring SaaS subscription model in a specialist vertical (church management) with a large, diversified customer base of 4,000+ churches globally. Its ~14-year operating history without signs of distress, combined with organic growth (no evidence of VC funding or significant debt), suggests the business is at least breakeven and likely profitable. High switching costs typical of church management software (data migration, staff training, Gift Aid integrations) reinforce customer stickiness and recurring revenue predictability. However, several risks constrain a higher score. The company faces vertical concentration in a mature market — UK church attendance is in long-term decline, limiting home-market TAM. Well-funded international competitors (Planning Center, Breeze ChMS, Tithe.ly, Rock RMS, ChurchTools) could out-invest ChurchSuite in product development. Additional risks include key-person/founder dependency, regulatory exposure to UK Gift Aid rules, payment-processor economics, and FX risk on international customers. Limited financial transparency also prevents external verification of margin trends and cash generation, which is a governance limitation for external stakeholders.
Key strengths: Recurring SaaS subscription revenue with high stickiness, Large diversified customer base of 4,000+ churches globally, 14-year operating history with continuous customer growth, Founder-led, self-funded/organic growth (no visible VC or debt raises), High switching costs in niche vertical (church management), Multi-geography reach: UK, Australia/NZ, US, Ireland
Risk factors: Limited financial transparency (small-company filing exemption), Mature/declining UK church attendance limits home-market TAM, Competitive pressure from VC-backed global competitors (Planning Center, Tithe.ly, Breeze ChMS, Rock RMS, ChurchTools), Dependency on Gift Aid rules and payment-processor economics, Key-person/founder risk with undisclosed executive depth, FX and international payments regulation risk
Revenue by geography
- United Kingdom: 70%
- Australia/New Zealand: 15%
- United States: 10%
- Ireland/Rest of Europe: 5%
Revenue by product/service
- SaaS Subscription (bundled modules: database, rotas, events, check-in, groups, planning, communications): 90%
- Giving & Gift Aid payment processing: 10%
Workforce by country
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.