Legal · effective September 11, 2026
Security & Trust
This page describes how NTL events, LLC ("NTL Events") hosts and protects the data that organizations manage with the platform. It states only what the platform does today. Where something depends on a contract, we say so.
1. Hosting and data location
- The application runs on Vercel. Server functions run in the iad1 region (Washington, D.C., USA).
- The database is PostgreSQL on Neon, hosted on AWS us-east-1 (Northern Virginia, USA).
- Payments are processed by Stripe. Card numbers are entered on Stripe and never pass through or are stored by NTL Events.
- By contract, customer data can be hosted and processed in the United States or the European Union. Support and administrative access can be provided from the United States, and administrative access to a customer's data can be restricted by contract to specific countries, with two-factor authentication and logging.
2. Encryption
- All traffic uses HTTPS (TLS). Browsers are told to always use HTTPS (HSTS).
- Our database provider encrypts data at rest with AES-256 and requires TLS for every connection.
- Documents that attendees upload during registration (for example, passports or invitation letters) are encrypted by NTL Events with AES-256-GCM before they are stored, and are only released through signed links that expire in minutes.
- Two-factor secrets are stored encrypted. Backup codes are stored only as one-way fingerprints.
3. Access control and authentication
- Each organization sees only its own events and attendees; every query is scoped to the account.
- Team roles: owner, administrator and box office (check-in only, no access to payouts).
- Two-factor authentication (TOTP, compatible with Google Authenticator, 1Password and Authy) with single-use backup codes. The account owner can make it mandatory for the whole team.
- Resetting someone's two-factor authentication requires an NTL administrator who has passed their own two-factor check and records a reason; the reset is logged and the user is notified by email.
4. Audit logging
- Every account has an access log: sign-ins and sign-outs, two-factor events, team changes, data exports, payout configuration changes, abstract decisions, registration approvals and downloads of attendee documents, with who, when, IP address and result.
- The log is append-only: the database rejects any change or deletion of a recorded entry. The owner can filter it and export it as CSV.
5. Backups
- The database provider keeps point-in-time restore backups in the same AWS region.
- NTL Events also keeps a secondary nightly copy (30-day rotation) on a server it operates in Mexico. Accounts with contractual data-residency requirements are excluded from that copy; their only backups are the provider's, in the USA.
6. Your data, your control
- The customer owns its event data. The platform is licensed; the data is not ours.
- Full export at any time: the account owner can download everything the platform holds for the account (events, registrations, answers, documents, abstracts and reviews, Attendee Hub, payments and access log) as CSV and JSON in a single archive, with a README describing every file and a checksum manifest. Two-factor authentication is required and each download is logged.
- Deletion on request: the owner can request deletion of the account. It is scheduled 30 days ahead (it can be cancelled until then), confirmed by NTL support, and ends with a signed certificate of deletion that lists what was deleted and what is kept (the append-only access log and backups until they expire).
- Documents uploaded at registration are deleted automatically when the retention period set for the event ends.
7. Artificial intelligence
- Registration, payments, abstract review, check-in, badges and the Attendee Hub use no facial recognition, biometrics, image verification, automated profiling or attendee matching.
- The organizer panel offers optional AI-assisted tools (an event-creation assistant and in-panel help). They only process the text the organizer types into them, never attendee records, and run only when the organizer opens them.
8. Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, file storage (Vercel Blob) | USA · functions in iad1 (Washington, D.C.) |
| Neon (Databricks) | PostgreSQL database | USA · AWS us-east-1 (N. Virginia) |
| Stripe | Payment processing (card data never reaches NTL Events) | USA / global |
| Resend | Transactional email | USA |
| Optional sign-in with Google (identity only) | USA / global | |
| Browser push services | Attendee Hub push notifications, only if the attendee allows them | Operated by each browser vendor |
Certifications held by these providers (for example, Stripe's PCI DSS Level 1) are theirs, not NTL Events'.
9. Assurance
NTL Events does not currently hold SOC 2 or ISO 27001 certification, and no independent penetration test report is available yet. We run our own automated checks: dependency vulnerability audits and OWASP ZAP baseline scans of the application, and we fix findings before release.
10. Incident notification
If we confirm a security incident that affects a customer's personal data, we notify the customer's account owner without undue delay and in any case within 72 hours of confirmation, with what happened, what data is affected, what we have done and what the customer should do. The customer, as controller of its attendees' data, decides on notifications to authorities and data subjects; we provide the information it needs.
11. Contact
Security and privacy questions, or to report a vulnerability: privacy@ntl.events. See also security.txt. Provider attestations (SOC 2, ISO 27001, PCI DSS) are shared under NDA on request through the contact form.
See also the Privacy Policy and the Terms of Service.