Security & trust
Built to pass your security review.
Your attendee and exhibitor data is yours, encrypted, access-controlled and hosted on infrastructure built for show day.
Principles
Six commitments. The same on every plan.
Data ownership
Every attendee, exhibitor and order is first-party data that belongs to the organizer. Export it in full at any time. Expola does not sell, share or market to your contacts.
Encryption
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Card data never touches Expola: payments are tokenised by PCI DSS Level 1 providers.
Access control
Single sign-on with SAML and OpenID Connect, enforced two-factor authentication, and role-based permissions down to a single event or report.
Infrastructure
Hosted on AWS in EU and US regions with automated backups, point-in-time recovery and a 99.9% uptime objective. Show days are load-tested in advance.
Privacy
A data processing agreement is part of every contract. Consent is captured at checkout and honoured across email, SMS and the app. Data subject requests are handled per contact.
Assurance
Annual third-party penetration testing, a responsible disclosure program, and audit logs for every change to an event's settings or data.
Controls
What your reviewer will ask about.
- Data residency
- EU (Frankfurt) or US (Virginia), chosen per account
- Backups
- Continuous, encrypted, retained 35 days, restore tested quarterly
- Authentication
- SSO (SAML 2.0, OIDC), enforced 2FA, session controls
- Permissions
- Roles per event, per module and per report; audit log of changes
- Payments
- PCI DSS Level 1 providers; no card data stored by Expola
- Availability
- 99.9% uptime objective; status page and incident notifications
- Vulnerability management
- Annual penetration test; dependency scanning; responsible disclosure
- Privacy
- GDPR data processing agreement; sub-processor list; DSAR tooling
Need the documentation?
Request our security overview, sub-processor list and the latest penetration test summary.