Skip to content

Security and privacy

Deal data is treated like personal data.

Deal sizes, fund sizes, and who is talking to whom are confidential. This page lists what protects them today and what we are hardening next. We would rather show you the list than a badge.

In place today

Current controls

Access

  • Invite-only registration. Each attendee registers from a personal, single-use invitation.
  • Role-based access for Independent Sponsors, Capital Providers, organizers, and administrators.
  • Mandate gates let Capital Providers block requests outside their criteria.
  • Delegation is granted by the attendee and can be revoked at any time.

Sign-in

  • Passwords hashed with Argon2.
  • Short-lived access tokens. Refresh tokens rotate on every use and live in an HttpOnly, Secure, SameSite=Strict cookie.
  • Rate limits on sign-in, registration, and invitation checks.

Data isolation

  • Each conference is a separate tenant. PostgreSQL row-level security enforces the boundary on conference-scoped tables.
  • Database access uses parameterized queries throughout.
  • Error responses are generic and do not expose internals.

Transport and browser

  • TLS on every connection, with HSTS.
  • Content Security Policy and frame-ancestors restrictions on API responses.
  • Cross-origin requests limited to an explicit allowlist of ConferenceDock domains.

Infrastructure

  • Hosted on Google Cloud: Cloud Run for the application, Cloud SQL for the database, encrypted at rest by Google Cloud.
  • Production secrets held in Google Secret Manager.
  • Deployments authenticate with workload identity federation, not long-lived keys.

Attendee safety

  • Attendees can block anyone. A blocked attendee cannot send them meeting requests.
  • Attendees whose requests are repeatedly declined are limited automatically.
  • Flagged messages surface to the organizer safety console.
In progress

Hardening in progress

Work under way or planned. We share status and dates on request.

ConferenceDock does not hold a third-party certification such as SOC 2 today. If your procurement process needs a security questionnaire, we will complete it.

  • Row-level security on every table

    Extending database-enforced isolation from conference-scoped tables to profiles and authentication tables.

  • Field-level encryption

    Application-level encryption for deal-sensitive fields such as deal size and fund details, on top of storage encryption.

  • Access audit log

    A record of who viewed sensitive profile data, and when.

  • Delegation in the database

    Enforcing delegate permissions at the database layer, in addition to the application.

  • Retention and deletion

    A published retention schedule and self-service deletion for attendees after an event.

  • Independent testing

    A third-party penetration test of the application and infrastructure.

Questions from your security team?

Bring them to the demo, or send them ahead and we will answer in writing.

Book a demo