Focus area · Data security & compliance

Specialised in church data protection.

Your strategic partner for data security and compliance: tailored to the strict requirements of church data protection law – proven, not just promised.

What you win

Security at the level required by church law.

  • Powerful and transparent

    Modern, scalable software with reliably high availability and permanently visible status.

  • ISO 27001 certification in preparation

    We have already initiated the certification process according to ISO 27001 – completion is expected in 2026.

  • Compliant with DSG-EKD and KDG

    ChurchDesk is compliant with the church data protection laws DSG-EKD and KDG.

  • Hosted in Germany

    ChurchDesk runs on Hetzner servers located in Germany – built by a team in Europe.

  • Secure login with SSO

    With single sign-on, your employees use their church login data – including a connection to Microsoft Entra ID.

  • In-house development team in Europe

    Our software is built and maintained by our own development team in Europe – no dependence on third parties.

For IT, CISO and data protection

The depth that your specialist departments expect.

Twelve security domains, contractually secured commitments and verifiable processes – for IT management, CISO and data protection officers.

For IT & data protection: all security details at a glance
  • MFA & SSO

    Multi-factor authentication and single sign-on with church identity provider.

  • Granular RBAC

    Fine-grained, church-specific role and rights model at all levels.

  • TLS & AES

    Encryption in transit (TLS) and at rest (AES).

  • Audit logs & SIEM

    Seamless logging and central security monitoring.

  • Pentests & Scans

    Annual external penetration tests and continuous vulnerability scanning.

  • Secure SDLC

    Secure development process including OWASP top 10 hardening.

  • EU hosting & sovereignty

    Hosting on Hetzner servers in Germany, development in Europe.

  • Georedundancy & DR

    Geo-redundant infrastructure and proven disaster recovery.

  • Incident Response

    Defined IR process with 24-hour reporting chain according to GDPR Art. 33.

  • ISO 27001 & GDPR

    GDPR compliant; ISO 27001 certification in preparation (expected to be completed during 2026).

  • AVV & TOMs

    AVV according to Art. 28 including complete TOM catalogue and subprocessor list.

  • Security culture

    Trained team and practiced safety culture across the entire organisation.

Contractually and verifiably secured

  • AVV according to Art. 28 including TOM catalogue and subprocessor list
  • DSG-EKD declaration of submission as standard
  • Native connection to Microsoft Entra ID including SCIM provisioning
  • Church-specific role and rights concept
  • Reporting chain according to GDPR Art. 33 within 24 hours

Hosted in Germany, built in Europe

Make member registry data usable – without compliance risk.

Our powerful API integrates your reporting system into ChurchDesk securely and in compliance with data protection regulations. This makes member registry data usable while maintaining the strict requirements of church data protection.

The data remains in Germany, the software is created in-house in Europe – in close cooperation with the data protection officers of your regional church or diocese.

  • Server in Germany – hosting at Hetzner
  • In-house development team in Europe
  • Compliant with DSG-EKD and KDG
  • Digital sovereignty without dependence on third parties
ChurchDesk is hosted on servers in Germany

Single sign-on

Secure login with the church identity provider.

With single sign-on, your employees log in via their existing church identity provider – without additional access data and without separate administrative effort for your IT.

You can control access centrally and in accordance with guidelines via the native connection to Microsoft Entra ID: authorisations follow your existing processes, entries and exits are mapped automatically.

  • Native connection to Microsoft Entra ID including SCIM provisioning
  • Centralised, policy-compliant access control
  • No additional login data for your employees
Single sign-on login in ChurchDesk with church identity provider

Availability & Transparency

Highly available – and transparent at all times.

Smooth operations are business-critical for your administration. ChurchDesk runs on a reliably highly available, geo-redundant infrastructure with proven disaster recovery.

You can publicly view the current status of all services at any time – for comprehensible operational security without questions.

To the status page
ChurchDesk's public status page with the current status of all services

Become a development partner.

Bring your church’s privacy and security needs directly into product development.

Become a development partner

Let’s talk about your compliance needs.

Arrange a conversation with our team or request the AVV and our security one-pager.