Going digital
Society software data security: 10 questions to ask before you sign up
Before you put years of member records and accounts into any software, ask these ten questions about data security, backups, access and exit. Plain answers, no jargon.
11 October 2026 5 min read
· Society Keeper Team
The committee has agreed to move the accounts online, and then someone at the back of the room asks the awkward question: "What happens to our data if their server crashes?" Nobody has an answer, so the decision gets postponed for another three months.
That question is a good one. Society software data security is not a technical detail to leave to the vendor; it is a committee responsibility. You are trusting someone with member phone numbers, years of dues history and every taka the association has spent. Below are ten questions to ask any provider, written so a non-technical treasurer can ask them and judge the answers.
Why the committee, not just the IT person, should ask
Most associations do not have an IT person at all. Even where a younger member "handles the computer side", the legal and moral duty to protect members' information sits with the elected committee. If records are lost or leaked, members will not blame the software; they will blame the people who chose it.
Asking these questions in writing also creates a record. If a future committee wonders why a particular system was chosen, the answers are on file.
Questions about where your data lives
1. Is our association's data kept separate from other customers?
Software that serves many associations should keep each one's records apart, so that a user at another society can never see your flats, members or ledgers. Ask how this separation is enforced, not just whether it exists.
2. Where are backups kept, and how often are they taken?
You want to hear that backups happen regularly and automatically, and that they are stored somewhere other than the main server. Ask how far back you could go if something were deleted by mistake.
3. Has a restore ever been tested?
A backup nobody has ever restored is a hope, not a plan. Ask whether the vendor periodically tests restoring data and how long a restore would take.
Questions about who can see and change what
4. Can we give each person their own login and role?
Shared logins are the single biggest everyday risk. Each collector, accountant and committee member should have a separate login with only the permissions their job needs. An auditor, for instance, should be able to view but not edit.
5. Is there an approval step for money entries?
A "maker-checker" process, where one person prepares a voucher and another approves it, protects against both honest mistakes and deliberate fraud.
6. Can we see who did what?
Every receipt and voucher should show who created it and when. Ask whether entries can be silently deleted, or whether corrections leave a trail.
7. How do members log in?
If members can view their own dues online, the login method matters. A one-time code (OTP) sent to the member's registered mobile is simpler for older members than a password and avoids password reuse.
Questions about leaving
8. Can we export our data to Excel at any time?
This is the question many committees forget. If you cannot take your member list, dues and reports out in a standard format, you are locked in. Ask to see the export working during the demo.
9. What happens to our data if we stop subscribing?
Get a clear, written answer on how long data is kept after cancellation and how you can obtain a final copy.
10. Who do we contact if something goes wrong?
You need a named channel (phone, email or WhatsApp) and a sense of how quickly they respond. During the first month you will use it more than you expect.
A simple scoring sheet
Print this and fill it in for each option you are considering:
| Question | Clear answer? | Shown in demo? | Notes |
|---|---|---|---|
| Data kept separate per association | |||
| Regular backups, stored separately | |||
| Individual logins and roles | |||
| Approval step for vouchers | |||
| Audit trail on entries | |||
| Excel export | |||
| Exit terms in writing |
Tip: Vague answers such as "don't worry, it's very secure" are a warning sign. A provider who takes security seriously can explain it in simple words.
What the association must do itself
Even the best software cannot protect you from weak habits. Make these committee rules:
- Close a person's login on the day they leave a post.
- Never share OTPs or passwords, even with the president.
- Export the key reports (member dues, trial balance, cash book) every month and keep a copy with two office bearers.
- Review the list of active users at each quarterly meeting.
That monthly export is your own independent backup. Say an association of 200 flats exports its dues list and ledger on the first Friday of each month: if anything ever went wrong, they would never lose more than a few weeks of records.
If your organisation is a cooperative society rather than an apartment association, Somity Keeper is built for savings, loans and instalment collection — and Somity Keeper Lite is the lightweight option for small groups.
How Society Keeper answers these questions
Society Keeper keeps each association's data separate, gives every user their own login with roles such as admin, manager, accountant, collector, committee and auditor, and uses maker-checker approval on vouchers. Members log in to their web app with mobile OTP, and reports can be exported to Excel whenever you like. Bring this list to a free demo and ask us the rest directly.
#data security #backup #society software #committee checklist