Security & Trust

Your event data,
handled like it matters.

An honest summary of how Confanum approaches security, privacy, and compliance. We're a young company — we're not going to claim certifications we don't yet hold, and we will tell you which controls are in place today and which are on the roadmap.

Controls in place today

🔐

Encryption in transit and at rest

TLS 1.2+ on every connection. AES-256 encryption at rest for stored data. Payment processor credentials encrypted with AES-256-CBC; cardholder data never touches our servers — Stripe, Square, and PayPal handle PAN directly.

🛡️

Tenant isolation

Every event is scoped to its company. Server-side ownership verification on event-scoped routes. IDOR protection on all cross-tenant references. Per-route permission enforcement on 90+ route mounts.

📋

Append-only audit log

Every money-touching action — ticket purchase, refund, transfer, comp — is recorded with actor, timestamp, and full context. Recursive secret redaction on every captured request. SOX-ready audit trail.

🔑

Role-based access control

Eight role presets, eleven permission keys, server-enforced on every route. Privilege escalation prevention — admins can only grant permissions they themselves hold. Default for moderators without a preset is fail-closed.

🌐

Privacy controls

GDPR + CCPA + CPRA: consent tracking, 30-day data access response window, right to deletion, data portability, in-app "Do Not Sell" opt-out, user-initiated account deletion from mobile.

👶

COPPA-aligned age gating

Three-tier age gate (under 13 / 13–17 / 18+) blocks data collection from minors before it starts. Children's data is not used for advertising, profiling, or data sharing.

🌎

Infrastructure

AWS multi-AZ deployment with managed databases (RDS), managed cache (ElastiCache), automated daily backups, point-in-time recovery, and active monitoring via New Relic + AWS CloudWatch. Data residency: United States.

⚙️

Application security

CSRF tokens on every mutating route. Parameterized SQL — no string-built queries. DOMPurify XSS protection. Content Security Policy headers. WebSocket rate limiting. Bcrypt password hashing.

On the roadmap

We are honest about what's not in place yet. These are the controls and certifications we are working toward, in approximate sequence:

Q2 2026

Mandatory MFA for admins

Multi-factor authentication required on every admin login, no exceptions. TOTP and WebAuthn supported.

Q2 2026

Daily payment reconciliation

Automated daily reconciliation against Stripe, Square, and PayPal records — drift surfaces in alerts.

Q3 2026

SOC 2 Type I (target)

Engagement with a SOC 2 readiness platform (Drata or Vanta). Sub-processor register and DPAs on file. Quarterly DR drill cadence established.

Q4 2026 – Q1 2027

SOC 2 Type II observation

Type II audit observation period; targeted Type II report by end of Q1 2027.

Roadmap dates are forward-looking and subject to change based on engineering capacity and customer requirements. We will update this page as milestones land.

Frequently asked

Are you SOC 2 certified?

Not yet. SOC 2 Type I targeted for Q3 2026, Type II for Q1 2027. We are happy to share our security questionnaire responses and walk through controls in detail.

Are you GDPR / CCPA compliant?

"Compliance" is a legal opinion that depends on your specific use case. Confanum has the controls in place to support GDPR and CCPA obligations: consent tracking, 30-day data access response window, right to deletion, data portability, "Do Not Sell" opt-out. We are happy to provide a Data Processing Addendum for customers who need one.

Where is data stored?

United States, on Amazon Web Services. RDS for primary data, ElastiCache for performance caching, S3 for media assets and backups, CloudFront for content delivery.

What payment providers do you support?

Stripe, Square, and PayPal. You connect your own merchant account — funds go direct to your bank. Confanum never holds your money. Cardholder data never touches our servers; tokenized references only.

Do you have an SLA?

We don't publish a default SLA. Enterprise customers can negotiate a written SLA as part of their contract. Our infrastructure is multi-AZ on AWS with automated failover and active monitoring.

How do I report a security issue?

Email security@confanum.com. We respond to every report and disclose remediation transparently to affected customers.

Got a security
questionnaire? Send it.

We respond to every security questionnaire in writing within five business days. No NDA needed for orientation; we'll execute one for any data-room contents.

Talk to us Privacy policy