Trust Center
Security and privacy you can verify
Conferences.Center handles submissions, reviews, attendee records, and payments for your events. This is where we document exactly how we protect that data — the controls we run, the partners we rely on, and the commitments we hold ourselves to. We aim to be precise and honest, including about the certifications we have not yet earned.
Trust resources
Everything you need to evaluate Conferences.Center from a security, privacy, and compliance standpoint — in one place.
Security
TLS everywhere, encrypted secrets, hardened authentication, and a defense-in-depth application design.
View security controlsPrivacy
Data minimization, self-service export and deletion, consent-backed analytics, and no third-party ad trackers.
Read privacy policyTerms of Service
The agreement that governs your use of the platform, written in plain, predictable language.
Read termsCookies
What we store in your browser and why. First-party analytics only, with consent surfaces for optional cookies.
Cookie policyData Retention
Current public beta handling for each data category, recoverable conference deletion, and rolling backups.
Retention scheduleSubprocessors
The third-party services we rely on to run the platform, what each one processes, and how to get change notifications.
View subprocessorsVulnerability Disclosure
Our responsible-disclosure policy, good-faith safe harbor, and how to report a security issue to our team.
Report a vulnerabilityAccessibility
Our WCAG 2.1 AA engineering target, automated and manual release checks, and barrier reporting.
Accessibility statementSystem Status
Current availability signals for the API and web app, with production readiness details.
Check statusOur standing commitments
These hold true across every plan, including the free tier.
- Encryption in transit (TLS) with HSTS on production responses
- Card data handled through Stripe-hosted checkout where payments are enabled — we never store card numbers
- Self-service data export and account deletion for every user
- First-party analytics only — no third-party advertising trackers
- Human-in-the-loop AI: assistance is advisory, never automatic decisions
- Honest compliance posture — we do not claim certifications we have not earned
Frequently asked questions
Is Conferences.Center SOC 2 or ISO 27001 certified?
Not currently. We do not claim SOC 2 or ISO 27001 certification. We describe current controls honestly and can discuss certification plans during procurement review.
Where is my data hosted?
The API and PostgreSQL database both run on Railway, the frontend is served by Vercel, and uploaded files use S3-compatible object storage. Public beta does not offer a customer-selected residency region. See our Subprocessors page for the current list.
Can I export or delete my data?
Yes. Every user can export their personal data (GET /users/me/export) and delete their account, which scrubs personal data. Some financial records are retained where required for legal and accounting obligations — see the Data Retention page.
How do I report a security vulnerability?
Email security@conferences.center with details and reproduction steps. We offer a good-faith safe harbor for responsible research. See our Vulnerability Disclosure page for scope and guidelines.
Have a specific compliance question?
Tell us your requirements and we will walk you through our current posture honestly.