Skip to main content
Back to Home

Security
Overview.

Last updated

How ConfWise protects organiser and attendee data. We update this page when our practices change.

Hosting and encryption

  • Our database, file storage and server code run on Google Firebase and Google Cloud. Cloudflare serves confwise.com and the ConfWise web app.
  • Data is encrypted in transit using HTTPS. It is stored with Google Cloud, which encrypts data at rest.
  • Development and production run in separate Firebase projects.
  • Server-side keys for our payment, email and AI providers are held in Google Secret Manager, not in our code. Production releases are deployed automatically by CI from our main branch.

Sign-in and access

  • Accounts use Firebase Authentication with email and password. You must verify your email before using Magic Import. We do not offer single sign-on or multi-factor authentication yet.
  • Firebase security rules control who can read and write each record. Only an event's organiser can change that event. Attendee records can be read only by the event's organiser and by the attendee themselves, and messages only by the people in the conversation.
  • Uploaded files are limited to images of up to 5 MB, and only their owner can upload or replace them.

Payments

Payments go through Stripe Checkout, hosted by Stripe. ConfWise never receives or stores your card number, and we verify Stripe's signature on every payment notification before upgrading an event.

AI processing

Magic Import sends the file you upload to Anthropic's API to extract your agenda, exhibitors, attendees or map. We check the file type first. We do not save the file to our storage, except a venue map image you choose to save, which is stored as event content. You review the result before it is published. Details are in our Privacy Policy.

Service providers

Service providers that process personal information for ConfWise
ProviderWhat for
Google (Firebase / Google Cloud)Sign-in (Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage), server code and its logs (Cloud Functions) and app analytics (Google Analytics for Firebase).
AnthropicAI extraction for Magic Import: turns uploaded agendas, exhibitor lists, attendee lists and venue maps into structured event data.
StripePayment processing through Stripe Checkout.
PostmarkTransactional email: email verification, password resets and support-request notifications.
CloudflareHosting and content delivery for confwise.com and the ConfWise web app (app.confwise.com).

Data deletion

Organisers can permanently delete an event and all of its sessions, speakers, exhibitors and attendee records from the dashboard. Images and in-app messages, and whole accounts, are deleted on request. See How long we keep it.

Report a security issue

Email support@confwise.com with “SECURITY” in the subject line. Organisers who need a data processing agreement can ask us at the same address.

Last updated