Security
Overview.
Last updated
How ConfWise protects organiser and attendee data. We update this page when our practices change.
Hosting and encryption
- Our database, file storage and server code run on Google Firebase and Google Cloud. Cloudflare serves confwise.com and the ConfWise web app.
- Data is encrypted in transit using HTTPS. It is stored with Google Cloud, which encrypts data at rest.
- Development and production run in separate Firebase projects.
- Server-side keys for our payment, email and AI providers are held in Google Secret Manager, not in our code. Production releases are deployed automatically by CI from our main branch.
Sign-in and access
- Accounts use Firebase Authentication with email and password. You must verify your email before using Magic Import. We do not offer single sign-on or multi-factor authentication yet.
- Firebase security rules control who can read and write each record. Only an event's organiser can change that event. Attendee records can be read only by the event's organiser and by the attendee themselves, and messages only by the people in the conversation.
- Uploaded files are limited to images of up to 5 MB, and only their owner can upload or replace them.
Payments
Payments go through Stripe Checkout, hosted by Stripe. ConfWise never receives or stores your card number, and we verify Stripe's signature on every payment notification before upgrading an event.
AI processing
Magic Import sends the file you upload to Anthropic's API to extract your agenda, exhibitors, attendees or map. We check the file type first. We do not save the file to our storage, except a venue map image you choose to save, which is stored as event content. You review the result before it is published. Details are in our Privacy Policy.
Service providers
| Provider | What for |
|---|---|
| Google (Firebase / Google Cloud) | Sign-in (Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage), server code and its logs (Cloud Functions) and app analytics (Google Analytics for Firebase). |
| Anthropic | AI extraction for Magic Import: turns uploaded agendas, exhibitor lists, attendee lists and venue maps into structured event data. |
| Stripe | Payment processing through Stripe Checkout. |
| Postmark | Transactional email: email verification, password resets and support-request notifications. |
| Cloudflare | Hosting and content delivery for confwise.com and the ConfWise web app (app.confwise.com). |
Data deletion
Organisers can permanently delete an event and all of its sessions, speakers, exhibitors and attendee records from the dashboard. Images and in-app messages, and whole accounts, are deleted on request. See How long we keep it.
Report a security issue
Email support@confwise.com with “SECURITY” in the subject line. Organisers who need a data processing agreement can ask us at the same address.