Security at Conferus
Effective October 2, 2026
How we protect the data organizations entrust to Conferus, and how to report a vulnerability.
Data protection
- All connections use HTTPS (TLS), and browsers are told to use HTTPS only (HSTS).
- Data is encrypted at rest by our database provider.
- Each organization's data is separated by row-level security rules enforced inside the database, not only in the application, and automated tests check that one organization can't read another's data.
- Card and bank account numbers are entered on Stripe's pages and never reach Conferus. Each organization's payments go to its own Stripe account.
- Only the last four digits of contractors' taxpayer numbers are stored.
Access control
- Each organization's administrators decide what each staff member can see and do, module by module.
- Passwords are stored only as salted hashes by our authentication provider.
- Repeated failed logins lock the account, and logins, sign-ups, password resets and public forms are rate-limited.
- Sensitive actions such as refunds, reversals and recording a member's death require specific permissions and are re-checked in the database.
Financial integrity
- Every change to financial records is written to an append-only activity log each organization can review.
- Closing a month locks its entries, so closed periods can't be changed by accident.
- Reconciliation of bank accounts, Stripe fees and Stripe payouts.
Application security
- Security headers, including a Content Security Policy, frame protection and a strict referrer policy.
- Rich text from users is sanitized before it is shown or emailed.
- Bulk emails and public content are reviewed automatically for prohibited material, and links are checked against Google Web Risk.
- Every change runs an automated test suite against a real database before release, and dependencies are monitored for known vulnerabilities.
- Errors are monitored so problems are found and fixed quickly.
Infrastructure
Conferus runs on established cloud providers (Vercel for the application, Supabase for the database, authentication and file storage), with managed backups. The full list of providers that handle data is on our Subprocessors page.
Independent testing and compliance
We plan to commission an independent penetration test and are working toward SOC 2 readiness. We will update this page as each is completed. Organizations can request our security documentation and answers to security questionnaires.
Report a vulnerability
If you believe you've found a security vulnerability in Conferus, please email security@conferus.net with the details and steps to reproduce it. We will acknowledge your report within 3 business days and keep you informed. Please don't access or change other people's data, disrupt the service or publicly disclose the issue before we've fixed it. We won't take legal action against good-faith research that follows these guidelines. Our security contact is also published at /.well-known/security.txt.
Questions? Write to legal@conferus.net.