VotrexOneSecurity & Trust

Security built for your church's data

Your church trusts VotrexOne with member records and giving. Here's exactly how we protect it — in plain English, no jargon. VotrexOne is operated by VotrexStudio LLC.

Compliance

Standards that matter for church giving & member data
PCI-DSS Level 1
All card data handled by Stripe
GDPR
Principles & data rights honored
CCPA
No sale or sharing of your data

Security controls

What we do to keep your data safe

Payments & giving

Giving flows into your church's own Stripe account — we never hold or touch your funds.
Card data is handled entirely by Stripe (PCI-DSS Level 1) — the highest tier.
Card numbers never touch our servers and are never stored by us.

Encryption

Encrypted at rest — the underlying storage is unreadable without the keys.
TLS in transit — every connection is served over HTTPS via Cloudflare.
Connected-account tokens are encrypted at the field level; passwords are salted and hashed.

Access & authentication

Two-factor authentication required for staff accounts that reach giving and member data.
Granular permissions — church admins control what each staff member can view or manage.
Least-privilege operator access, with sensitive actions logged.

Data & infrastructure

Per-church isolation — one church can never see another's people, giving, or messages.
Nightly encrypted offsite backups of your database and media.
Our database is not exposed to the public internet.

Sub-processors

Vetted providers that help deliver the service
StripePayment processing for online giving and subscriptionsUSA
CloudflareContent delivery, TLS, network protection, and encrypted backup storageUSA
AnthropicAI selection of clip-worthy sermon segmentsUSA
ResendTransactional and church-branded email deliveryUSA
Firebase Cloud MessagingMobile push notificationsUSA
YouTube & Meta APIsPublishing to a church's own channel/Page, when connectedUSA
MapboxAddress autocomplete and maps for location fieldsUSA

A full sub-processor list is in our Data Processing Addendum.

FAQ

Do you encrypt data at rest?
Yes. Data is stored on encrypted-at-rest storage, and sensitive credentials (like connected-account tokens) are additionally encrypted at the field level.
Do you encrypt data in transit?
Yes. Every connection to votrexone.com is served over TLS (HTTPS), fronted by Cloudflare.
Do you store card numbers?
No. All card data is handled by Stripe, a PCI-DSS Level 1 certified provider. Card details are entered directly into Stripe and never reach our servers.
How is our giving money protected?
Your giving flows into your church's own Stripe account and pays out directly to your church's bank. VotrexOne never holds, pools, or has access to your funds.
Can church staff read members' direct messages?
No. Direct messages are private from staff — there is no chat-review screen in the dashboard, and access is limited to the people in the conversation. See our Privacy Policy for full detail.
How do I report a security vulnerability?
Email [email protected] with the details and we'll respond promptly. Please give us a reasonable chance to address it before disclosing publicly.
An honest note. No system is perfectly secure, and any company that says otherwise isn't being straight with you. What we promise is that we take measures appropriate to the sensitivity of church data — encryption, isolation, backups, and two-factor access — and keep improving them as VotrexOne grows.