Legal · effective September 11, 2026
Trust center
NTL events, LLC ("NTL Events") built this page so an institution evaluating the platform can find, in one place, where its data lives, who else touches it, and what is and isn't verified yet. It only states what is true today. For the full technical detail, see Security & Trust.
1. Residency and hosting
- Application servers run on Vercel, in the iad1 region (Washington, D.C., USA).
- The database is PostgreSQL on Neon, hosted on AWS us-east-1 (Northern Virginia, USA).
- By contract, customer data can be hosted and processed in the United States or the European Union, and administrative access to a customer's data can be restricted to specific countries, with two-factor authentication and logging. See section 1 of Security & Trust for the full statement.
2. Subprocessors and their certifications
These are the providers NTL Events relies on to run the platform. The certifications listed below belong to each provider, not to NTL Events — we link to the provider's own security page so you can verify it directly rather than take our word for it.
| Provider | Used for | Provider's certifications (source) |
|---|---|---|
| Vercel Inc. | Application hosting and file storage (Vercel Blob) | SOC 2 Type 2, ISO 27001:2013, PCI DSS (SAQ-D for service providers, SAQ-A for merchants, v4.0), GDPR, EU-US Data Privacy Framework, TISAX Level 2. HIPAA support available for enterprise customers. (vercel.com/security) |
| Neon (Databricks) | PostgreSQL database | Aligned to SOC 2, ISO 27001, ISO 27701, GDPR and CCPA, with annual SOC 2 / ISO audits by two independent firms and a biannual penetration test with HackerOne. Encryption at rest (AES-256) and in transit (TLS 1.2/1.3). (neon.com/docs/security/security-overview) |
| Stripe | Payment processing (card numbers never reach NTL Events) | PCI Service Provider Level 1 (the strictest tier), SOC 1 and SOC 2 Type II annually (available on request) plus a public SOC 3, aligned to the NIST Cybersecurity Framework, EU-US DPF / UK extension / Swiss-US DPF. (docs.stripe.com/security/stripe) |
| Resend | Transactional email | SOC 2 Type II (audited by Vanta & Advantage Partners), GDPR-compliant, encryption at rest and TLS 1.3+. Resend states it does not currently hold HIPAA or ISO 27001 — we repeat that here rather than round it up. (resend.com/security) |
| Optional “Sign in with Google” (identity only, no attendee data shared) | Google Cloud / Workspace maintains SOC 2 and ISO 27001 certifications. See Google's own compliance page for the current, authoritative list — we don't quote it here to avoid misquoting. (cloud.google.com/security/compliance) |
A short list of dependencies we reviewed and excluded because they don't apply to ntl.events: Razorpay (India-market consumer payments, not used here) and Mapbox (not used on any page reachable from ntl.events). We'd rather list fewer subprocessors accurately than list more to look bigger.
3. Our own controls
Encryption, access control, two-factor authentication, audit logging, backups, data export and deletion, and how we use (and don't use) artificial intelligence are all controls NTL Events operates directly, not inherited from a subprocessor. They are documented with evidence in Security & Trust, which we treat as a living page: it changes when the product changes, not once a year.
4. Service levels
Support response and resolution targets by priority, coverage hours and support channels are published at Service levels.
5. Incident notification
How and when NTL Events notifies a customer of a confirmed security incident is described in section 10 of Security & Trust.
6. Accessibility
Our WCAG 2.1 AA conformance report, method and known gaps are published at Accessibility.
7. Roadmap
We would rather say "not yet" than imply something we can't back up:
- SOC 2 Type II (NTL Events, LLC): planned, not started. No auditor is engaged yet.
- Independent penetration test: planned, not started. No test has been run against the platform by a third party.
- Until either exists, our own testing is limited to dependency vulnerability audits and OWASP ZAP baseline scans of the application before release (see section 9 of Security & Trust).
8. Contact
Questions about this page, or to request a subprocessor's attestation under NDA: privacy@ntl.events or the contact form.
See also the Privacy Policy and the Terms of Service.