Security and privacy
Deal data is treated like personal data.
Deal sizes, fund sizes, and who is talking to whom are confidential. This page lists what protects them today and what we are hardening next. We would rather show you the list than a badge.
Current controls
Access
- Invite-only registration. Each attendee registers from a personal, single-use invitation.
- Role-based access for Independent Sponsors, Capital Providers, organizers, and administrators.
- Mandate gates let Capital Providers block requests outside their criteria.
- Delegation is granted by the attendee and can be revoked at any time.
Sign-in
- Passwords hashed with Argon2.
- Short-lived access tokens. Refresh tokens rotate on every use and live in an HttpOnly, Secure, SameSite=Strict cookie.
- Rate limits on sign-in, registration, and invitation checks.
Data isolation
- Each conference is a separate tenant. PostgreSQL row-level security enforces the boundary on conference-scoped tables.
- Database access uses parameterized queries throughout.
- Error responses are generic and do not expose internals.
Transport and browser
- TLS on every connection, with HSTS.
- Content Security Policy and frame-ancestors restrictions on API responses.
- Cross-origin requests limited to an explicit allowlist of ConferenceDock domains.
Infrastructure
- Hosted on Google Cloud: Cloud Run for the application, Cloud SQL for the database, encrypted at rest by Google Cloud.
- Production secrets held in Google Secret Manager.
- Deployments authenticate with workload identity federation, not long-lived keys.
Attendee safety
- Attendees can block anyone. A blocked attendee cannot send them meeting requests.
- Attendees whose requests are repeatedly declined are limited automatically.
- Flagged messages surface to the organizer safety console.
Hardening in progress
Work under way or planned. We share status and dates on request.
ConferenceDock does not hold a third-party certification such as SOC 2 today. If your procurement process needs a security questionnaire, we will complete it.
-
Row-level security on every table
Extending database-enforced isolation from conference-scoped tables to profiles and authentication tables.
-
Field-level encryption
Application-level encryption for deal-sensitive fields such as deal size and fund details, on top of storage encryption.
-
Access audit log
A record of who viewed sensitive profile data, and when.
-
Delegation in the database
Enforcing delegate permissions at the database layer, in addition to the application.
-
Retention and deletion
A published retention schedule and self-service deletion for attendees after an event.
-
Independent testing
A third-party penetration test of the application and infrastructure.
Questions from your security team?
Bring them to the demo, or send them ahead and we will answer in writing.