New: the AI assistant answers exhibitor calls.Read more
Expola

Security & trust

Built to pass your security review.

Your attendee and exhibitor data is yours, encrypted, access-controlled and hosted on infrastructure built for show day.

Principles

Six commitments. The same on every plan.

  • Data ownership

    Every attendee, exhibitor and order is first-party data that belongs to the organizer. Export it in full at any time. Expola does not sell, share or market to your contacts.

  • Encryption

    Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Card data never touches Expola: payments are tokenised by PCI DSS Level 1 providers.

  • Access control

    Single sign-on with SAML and OpenID Connect, enforced two-factor authentication, and role-based permissions down to a single event or report.

  • Infrastructure

    Hosted on AWS in EU and US regions with automated backups, point-in-time recovery and a 99.9% uptime objective. Show days are load-tested in advance.

  • Privacy

    A data processing agreement is part of every contract. Consent is captured at checkout and honoured across email, SMS and the app. Data subject requests are handled per contact.

  • Assurance

    Annual third-party penetration testing, a responsible disclosure program, and audit logs for every change to an event's settings or data.

Controls

What your reviewer will ask about.

Data residency
EU (Frankfurt) or US (Virginia), chosen per account
Backups
Continuous, encrypted, retained 35 days, restore tested quarterly
Authentication
SSO (SAML 2.0, OIDC), enforced 2FA, session controls
Permissions
Roles per event, per module and per report; audit log of changes
Payments
PCI DSS Level 1 providers; no card data stored by Expola
Availability
99.9% uptime objective; status page and incident notifications
Vulnerability management
Annual penetration test; dependency scanning; responsible disclosure
Privacy
GDPR data processing agreement; sub-processor list; DSAR tooling

Need the documentation?

Request our security overview, sub-processor list and the latest penetration test summary.

Request security documentation