ChurchSuite

United Kingdom · churchsuite.com · 19 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 19 sub-vendors.

Insights

Last updated 2026-07-01 · revision 2

19 direct vendors, 261 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ChurchSuite exhibits high migration readiness, primarily due to its existing cloud-native and multi-cloud infrastructure across Amazon Web Services (AWS), Google Cloud Platform, and Digital Ocean. This indicates a mature cloud adoption strategy and significant flexibility for migrating or re-platforming services. The use of a RESTful web application architecture and automated testing (CI) further streamlines potential migration efforts. Per-account database segregation also simplifies data migration processes. The company's diverse vendor ecosystem for critical services (e.g., Ably, Twilio, Mailgun, Stripe) suggests a lower risk of vendor lock-in compared to relying on a single, integrated platform, allowing for easier component swapping or re-integration during a migration. While the specific details on data residency requirements and the broader regulatory environment (beyond GDPR compliance) are not provided, and explicit vendor lock-in risk is unknown, the current technological foundation strongly positions ChurchSuite for efficient and effective migrations.

Compliance

8 in-scope frameworks identified; showing 3.

Australian Privacy Act 1988 — Assessment Required

ChurchSuite explicitly operates an Australian site variant (au.churchsuite.com), indicating active operations and customer acquisition in Australia. The Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) apply to organisations with annual turnover exceeding AUD $3 million, or to organisations that handle health information or certain other sensitive data. Churches using ChurchSuite in Australia would be Data Controllers, and ChurchSuite would be a service provider processing personal data on their behalf. The risk is Medium because: (1) ChurchSuite clearly has Australian operations, (2) the Privacy Act obligations for service providers handling Australian personal data are significant, (3) no Australian-specific privacy compliance documentation was found, (4) the 2022 Privacy Act Review recommendations (if enacted) would significantly expand obligations.

Evidence: https://churchsuite.com/

SOC 2 (source) — Assessment Required

ChurchSuite is a cloud SaaS provider processing sensitive personal data (church membership, children's data, financial/donation records) for thousands of organisations. SOC 2 is highly relevant for cloud service providers and is increasingly expected by enterprise customers and data protection-conscious organisations. No SOC 2 Type I or Type II report was found in public sources. The risk is Medium because: (1) absence of SOC 2 certification is a gap for a cloud SaaS provider handling sensitive data, (2) larger church customers or those with formal governance requirements may require SOC 2 evidence, (3) however, ChurchSuite's primary customer base (churches) may not typically demand SOC 2, reducing immediate commercial risk. The company does conduct annual CREST-approved penetration testing, which partially addresses security assurance needs.

Evidence: https://churchsuite.com/security, https://churchsuite.com/gdpr

UK Children's Code — Assessment Required

ChurchSuite explicitly provides a children's ministry module with 'secure check-in for children and visitors' and processes children's personal data. The UK Children's Code (ICO's Age Appropriate Design Code) applies to online services likely to be accessed by children under 18. While ChurchSuite is a B2B platform (churches are the customers, not children directly), the platform processes children's data on behalf of churches and includes child-facing or child-data-processing features. Risk is High because: (1) children's data is among the most sensitive categories under UK GDPR, (2) the ICO has been actively enforcing the Children's Code, (3) any gaps in how children's data is handled (consent, data minimisation, retention) could result in significant regulatory action, (4) the platform explicitly markets children's ministry features including check-in systems.

Evidence: https://churchsuite.com/, https://churchsuite.com/gdpr, https://churchsuite.com/tour/children

Financials

Three-year financials

Financial Resilience Score: 7/10

ChurchSuite Ltd demonstrates strong qualitative financial resilience despite the absence of publicly disclosed financial figures due to UK small-company filing exemptions. The company operates a recurring SaaS subscription model in a specialist vertical (church management) with a large, diversified customer base of 4,000+ churches globally. Its ~14-year operating history without signs of distress, combined with organic growth (no evidence of VC funding or significant debt), suggests the business is at least breakeven and likely profitable. High switching costs typical of church management software (data migration, staff training, Gift Aid integrations) reinforce customer stickiness and recurring revenue predictability. However, several risks constrain a higher score. The company faces vertical concentration in a mature market — UK church attendance is in long-term decline, limiting home-market TAM. Well-funded international competitors (Planning Center, Breeze ChMS, Tithe.ly, Rock RMS, ChurchTools) could out-invest ChurchSuite in product development. Additional risks include key-person/founder dependency, regulatory exposure to UK Gift Aid rules, payment-processor economics, and FX risk on international customers. Limited financial transparency also prevents external verification of margin trends and cash generation, which is a governance limitation for external stakeholders.

Key strengths: Recurring SaaS subscription revenue with high stickiness, Large diversified customer base of 4,000+ churches globally, 14-year operating history with continuous customer growth, Founder-led, self-funded/organic growth (no visible VC or debt raises), High switching costs in niche vertical (church management), Multi-geography reach: UK, Australia/NZ, US, Ireland

Risk factors: Limited financial transparency (small-company filing exemption), Mature/declining UK church attendance limits home-market TAM, Competitive pressure from VC-backed global competitors (Planning Center, Tithe.ly, Breeze ChMS, Rock RMS, ChurchTools), Dependency on Gift Aid rules and payment-processor economics, Key-person/founder risk with undisclosed executive depth, FX and international payments regulation risk

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report