Security Settings

Security Settings

Audience: This article is for church administrators.

TimelyChurch takes the security of your church's data seriously. This guide covers the security features available to protect your account, your team members' accounts, and your congregation's information.


Two-Factor Authentication (2FA)

Two-factor authentication adds an extra layer of security to user accounts by requiring a time-based verification code in addition to the password when logging in.

How 2FA Works

TimelyChurch uses TOTP (Time-based One-Time Password) two-factor authentication, which is compatible with popular authenticator apps:

  • Google Authenticator
  • Microsoft Authenticator
  • Authy
  • 1Password
  • Any TOTP-compatible app

When 2FA is enabled, after entering your password you will also need to enter a 6-digit code from your authenticator app.

Enabling 2FA

Each user enables 2FA for their own account from the member portal.

  1. Log in and go to Member Portal > Profile.
  2. Open the Security section. (See Managing Your Profile for the full profile walkthrough — the Security section there covers 2FA.)
  3. Click Enable Two-Factor Authentication. The system displays a secret key and a QR code.
  4. Open your authenticator app and scan the QR code (or manually enter the secret key).
  5. Enter the 6-digit code from your authenticator app and submit to finalize setup.
  6. Save the recovery codes that are generated -- these are one-time-use codes that let you access your account if you lose access to your authenticator app. You can regenerate them later from the same Security section.

Important: Store your recovery codes in a safe place (such as a password manager or a printed copy in a secure location). Each recovery code can only be used once.

Using 2FA to Log In

  1. Enter your email and password as usual.
  2. When prompted, open your authenticator app.
  3. Enter the current 6-digit code displayed in the app.
  4. Click Verify to complete login.

Using a Recovery Code

If you lose access to your authenticator app (e.g., lost phone, new device):

  1. On the 2FA verification screen, look for a Use Recovery Code option.
  2. Enter one of your saved recovery codes.
  3. The code will be consumed (each code works only once).

After logging in with a recovery code, set up 2FA again with your new device as soon as possible.

Disabling 2FA

If you need to disable two-factor authentication:

  1. Go to Member Portal > Profile and open the Security section.
  2. Click Disable Two-Factor Authentication.
  3. Confirm the action.

Tip: We strongly recommend keeping 2FA enabled, especially for users with Administrator roles who have access to sensitive church data and configuration.


Support PIN Verification

Every church in TimelyChurch has a unique Support PIN -- a 6-digit code used to verify your identity when contacting customer support.

Where to Find Your Support PIN

  1. Go to Settings in the admin panel.
  2. On the Profile tab, scroll to the Support Verification section.
  3. Your Church ID and Support PIN are displayed.
  4. Use the copy button to copy either value to your clipboard.

When to Use Your Support PIN

You will be asked for your Support PIN when:

  • Contacting TimelyChurch support via email or chat
  • Requesting account changes that require identity verification
  • Requesting data exports or account-level modifications through support

Regenerating Your Support PIN

If you believe your Support PIN has been compromised:

  1. Go to Settings > Profile.
  2. In the Support Verification section, click the regenerate (refresh) icon next to the PIN.
  3. Confirm the regeneration.
  4. A new 6-digit PIN will be generated and the old one immediately invalidated.

The regeneration is logged in the system's audit trail for accountability.

Security Warning: Never share your Support PIN publicly -- in forums, on social media, or in unsolicited communications. Only provide it to verified TimelyChurch support staff.


Account Security Best Practices

For Administrators

  1. Enable 2FA on all administrator accounts. Administrators have full access to church data and settings. Protecting these accounts with 2FA is critical.

  2. Have at least two administrators. If one administrator loses access, the other can help recover the account. The system prevents you from removing the last administrator.

  3. Review team member access regularly. Periodically visit the Team Management page to verify that team members have appropriate roles. Remove access for anyone who has left the church or no longer needs it.

  4. Use the principle of least privilege. Assign the most restrictive role that still allows someone to do their job. A Sunday School teacher does not need access to financial data.

  5. Deactivate accounts for temporary absences. If someone is on sabbatical or leave, deactivate their account rather than leaving it active.

For All Team Members

  1. Use a strong, unique password. Do not reuse passwords from other services.

  2. Enable two-factor authentication. This is the single most effective step you can take to secure your account.

  3. Do not share your login credentials. Each person should have their own account with appropriate permissions.

  4. Log out when using shared devices. If you access TimelyChurch from a shared computer, always log out when finished.


Data Privacy and Protection

Multi-Tenant Isolation

Every church's data in TimelyChurch is isolated by a church-specific identifier. This means:

  • One church cannot see another church's people, events, or financial data
  • All data access is automatically scoped to your church's records
  • Team members can only access data for churches they are explicitly invited to

Encrypted Storage

  • Support PINs and sensitive configuration values are stored securely
  • Two-factor authentication secrets are encrypted at rest
  • Payment card information is handled by Stripe and never stored on TimelyChurch servers

Role-Based Access Control

As described in the Roles & Permissions guide, every action in TimelyChurch is checked against the user's assigned role. This ensures that:

  • A team member can only access modules their role permits
  • Scope restrictions (own records, team, or all) limit the data they can view
  • Administrative actions (like managing settings or inviting team members) are reserved for appropriate roles

Audit Logging

TimelyChurch logs sensitive actions in two places:

  1. A general activity stream that records changes across most of your records (people, schedules, finances, etc.).
  2. A separate, tamper-evident log for platform-level events.

Tracked events include support PIN regeneration, team member additions/removals/role changes, subscription changes, custom domain verification, and many record-level edits.

Coming soon for church admins: There is currently no in-app UI for church administrators to browse their own audit log. The data is being captured today, but only TimelyChurch platform support (super admins) can view it via the internal admin tools. If you need a copy of recent activity for your church, contact support with your Church ID and Support PIN. A self-serve audit log viewer for church admins is on the roadmap.


Custom Domain Security (Pro Plan and Above)

If your church uses a custom domain for public-facing pages, the domain verification process includes security checks:

  1. TXT Record Verification -- You must add a unique verification token as a DNS TXT record to prove domain ownership.
  2. CNAME/A Record Verification -- You must point your domain to TimelyChurch's servers.
  3. Both records must be verified before the custom domain becomes active.

This prevents anyone from claiming a domain they do not control.


Frequently Asked Questions

Q: Is 2FA required for all users? A: Two-factor authentication is currently optional and can be enabled by each user individually. We strongly recommend it for all accounts, especially administrators.

Q: What if I lose my phone and my recovery codes? A: Contact TimelyChurch support with your Church ID and have another administrator on your team verify your identity. Support can help reset your 2FA so you can set it up again.

Q: How is my church's data backed up? A: TimelyChurch maintains regular database backups as part of the platform infrastructure. You can also export your own data at any time through the Export tab in Settings.

Q: Can I see who logged into my church's admin panel? A: Logins and other sensitive actions are captured in the audit log, but church admins do not currently have a UI to browse this log themselves. Contact TimelyChurch support with your Church ID and Support PIN if you need a detailed access log for your church. (A self-serve audit log viewer is on the roadmap.)

Q: Is TimelyChurch compliant with data protection regulations? A: TimelyChurch is built with security best practices including multi-tenant data isolation, encrypted storage, role-based access control, and TOTP-based two-factor authentication. The platform uses Stripe for PCI-compliant payment processing.

We use cookies to personalize your experience. By continuing to visit this website you agree to our use of cookies

More