Skip to content
Journal
Choosing software

Is our parish data safe? A plain guide to parish data security

The Symphonia team · July 26, 2026

When a parish moves its records into software, a fair question comes up at the council table: is our data safe? It is the right question, and it deserves a plain answer rather than a wall of certification logos. Parish data security is not mysterious. It comes down to a few concrete things — whether your parish's records are kept apart from everyone else's, whether they are encrypted, who exactly can see them, and whether you can take them with you. This is a non-technical guide to those questions, written for clergy and council members who have to make the decision without being engineers.

What parish data security actually means

Strip away the jargon and security is really four plain questions.

  • Is our data kept apart from other parishes, or pooled with everyone's?
  • Is it encrypted, so a stolen hard drive is not a stolen directory?
  • Who can see what — which staff and volunteers can view giving, addresses, pastoral notes?
  • Can we take it and leave?

A vendor who can answer those four in ordinary words is being honest with you. A vendor who answers only with badge images and acronyms may be hoping you will not ask the plain version. You are allowed to insist on the plain version.

Isolation: your parish is not in a shared pile

Some platforms put every church's records into one large shared database, separated only by a label on each row. It usually works — until a query is written wrong and one congregation sees another's data.

Stronger isolation keeps each parish's records genuinely apart, so there is no path from one parish's screen to another's, even by mistake. Symphonia runs with per-parish isolation for exactly this reason: your directory, your giving, your register are yours and structurally separated from every other parish on the system. You can read how that is arranged on the security page.

Encryption: what a stolen disk gets

Encryption at rest means the data sitting on the server's disks is stored scrambled, not as plain text. If someone walked out with the physical drive, they would hold noise, not your members' home addresses.

This is table stakes, and you should expect it from any serious vendor. The useful follow-up is what is encrypted — everything, or only passwords? — and whether the most sensitive records get an extra layer. Which brings us to the part most software gets wrong.

Who can see what — and sealed pastoral records

Not everyone who helps run a parish should see everything in it. The volunteer updating the directory does not need giving amounts. The treasurer does not need the priest's pastoral notes. Good software makes these permissions granular, so people see what their role requires and no more.

The most sensitive records deserve more than a permission setting. A priest's private pastoral notes — the kind of thing kept under the seal — should be sealed to the priest: encrypted so that no administrator, no staff member, and no one at the software company can read them. In Symphonia those sealed notes are encrypted to the priest, not merely hidden behind a checkbox. The difference matters. A checkbox can be unchecked. Envelope encryption cannot be quietly overridden.

This is the point where fit and security meet. A generic CRM has no concept of a pastoral record under seal, so it stores such notes like any other field — readable by whoever holds admin access. A parish-native system treats them as what they are.

Ownership and export

Security is not only about keeping data from the wrong people. It is also about keeping it available to the right ones — you.

Ask plainly: do we own our records, and can we export all of them, whenever we want, in a standard format? The answer should be an unqualified yes. Data you cannot leave with is data you do not really control. Symphonia is built so the parish owns its data and can export the whole of it — members, giving, the sacramental register, the books — at any time. Being early with a beta product should never mean being locked in.

What to ask, honestly

A short, fair way to end every vendor conversation:

  • Is each parish's data isolated from the others?
  • Is it encrypted at rest, and what exactly is covered?
  • Can pastoral notes be sealed so even you, the vendor, cannot read them?
  • Are staff permissions granular?
  • Can we export everything and leave?

We would rather answer these than dodge them, and we try to say plainly what we do and do not yet do — the honest details are on the security features page. A parish is trusting its software with baptisms, with confidences kept under seal, and with the giving of its people. That trust is worth a few direct questions, asked of every vendor, including this one.