Security for churches and charities that hold real trust
You handle donations, pastoral records, and safeguarding data, usually without a dedicated IT person and always on a tight budget. Here's what an automated scan catches for free, and what genuinely needs a human.
// why this matters for churches & charities
Trust is the whole point — donors, congregation members, and volunteers give you their money and their details because they believe you'll look after them. A spoofed appeal email or an exposed donor list undoes that trust fast, and most churches and charities simply don't have the budget for enterprise security tooling. The automated scan is built to be affordable first.
Giving and donation pages
AutomatedWhether donations run through an embedded widget, a link to a giving platform, or your own form, the scan checks the page serving it enforces HTTPS properly, has no mixed content warnings, and carries sane security headers — the basic hygiene a donor's browser is quietly checking too.
Impersonation of the church or charity by email
AutomatedA fake urgent appeal "from the treasurer" or "from the minister" asking for an emergency transfer is one of the most common scams charities face. SPF, DKIM, and DMARC on your domain are what stop someone spoofing your email address to send it — checked on every scan.
Old CMS versions and exposed files
AutomatedMany church and charity sites are built once, by a volunteer, on WordPress or a similar platform, and rarely updated after. The scan fingerprints outdated CMS/plugin versions and probes for leftover config files, debug logs, and backup archives left behind by old migrations.
Sermon archives and safeguarding records
Manual / advisoryWho can actually open the shared Google Drive or Dropbox folder holding sermon recordings or safeguarding files isn't something a website scan can see. That's a settings and permissions review, not an automated check — we cover it as part of a Local Business Package review.
Volunteer and shared account access
Manual / advisoryVolunteers come and go, and shared logins that never get rotated are a common, quiet risk. It's a process question rather than something visible from outside your site, so it's advisory guidance rather than an automated finding.
Every “Automated” item above runs as part of the standard Security Score scan — see the full technical checklist. “Manual / advisory” items are covered as part of our Local Business Package and GDPR Readiness Assessment, priced to be realistic for a charity budget.
// ready?
See where your site and email stand, at no cost
Free automated scan, one-page report in 24 hours, no commitment. Ongoing monitoring starts at £20/month if you want it kept up to date.