This page is the maintained description of the technical and organizational
measures referenced by our Privacy Policy and
DPA (Article 32). We may update these measures
provided the level of protection is not reduced.
Encryption
In transit. TLS on all connections to the Service and its API.
Backups. Backups are encrypted before they leave the host, and are stored in a European Union region.
Access control & authentication
Role-based access control within the Service, enforced at the application layer.
Organizer and attendee sign-in is handled by our identity provider (Hanko), which supports passwordless and passkey/multi-factor authentication.
Administrative access to infrastructure is restricted to Kevin Buoren Shiue and protected by SSH key authentication.
Network & isolation
The application and database run in containers on a private network; the database is not directly reachable from the internet.
The Service is multi-tenant: each Organization’s data is logically separated and access is enforced at the application layer.
Data location
Hosting (Hetzner, Germany), email (Scaleway, France), file storage (Google Cloud, EU region), and authentication (Hanko, EU region) all use European regions.
Backups & resilience
Daily backups, encrypted before leaving the host, retained for 30 days.
Restoration is tested monthly and the result recorded.
Logging & retention
Application and access logs are retained for 30 days.
Authentication and security events are retained for 90 days.
Patching
Operating-system security updates are applied on a regular basis; dependency updates are reviewed and applied periodically.
Breach handling
No system is perfectly secure. If a breach affects personal data and is likely
to result in a high risk to the rights of individuals, we will notify without
undue delay, as set out in the DPA and Privacy Policy.