Security
How we protect your data, and how to tell us if something looks wrong.
Report a security issue
If you believe you have found a vulnerability, or you suspect a security incident affecting Conferfly or your data, email [email protected] with as much detail as you can: what you saw, when, and how to reproduce it.
- We aim to acknowledge reports within 3 business days.
- Please give us reasonable time to fix an issue before sharing it publicly.
- Please do not access, change or delete other customers' data, and do not disrupt the service while testing.
Our machine-readable contact is at /.well-known/security.txt.
How we protect your data
- Encryption. Traffic to Conferfly uses TLS 1.3 with HSTS. Stored data is encrypted at rest on Google Cloud, and Google and Microsoft access tokens are additionally encrypted by the application before they are stored.
- Hosting. Conferfly runs on Google Cloud in the United States, behind Cloudflare for DNS, DDoS protection and a web application firewall.
- Calendar data. Meeting information is read live from your Google or Microsoft calendar to display it. It is not stored persistently.
- Screen sharing. Wireless screen sharing is an encrypted real-time stream. It is not recorded or stored.
- Access. Multi-factor authentication is required on the systems that hold company and customer data, access is limited to what each person needs, and we review access every quarter.
- Development. Code changes go through pull requests with review, and we scan for leaked secrets and vulnerable dependencies.
- Incidents. We maintain and test an incident response plan, and we notify affected customers without undue delay.
Privacy and legal
Read our Privacy Policy and Terms of Service. For privacy requests, email [email protected].