Attendae
← Legal center 🇲🇽 ES

Legal center → Security Policy

Security Policy

How Attendae protects institutional and participant data

Contents

  1. Security principles
  2. Administrative measures
  3. Technical measures
  4. Physical security
  5. Confidentiality
  6. Incident response
  7. Limitations and shared responsibility
  8. Security contact

1 Security principles

Attendae's security program is built on the following principles:

Confidentiality

Personal and institutional data is accessible only to authorized parties with a legitimate need.

Integrity

Data is protected against unauthorized modification, corruption, or deletion.

Availability

Services are designed for high availability as committed in the SLA.

Minimum privilege

Users and processes are granted only the access permissions required for their specific function.

Defense in depth

Multiple overlapping security controls ensure no single point of failure can compromise the system.

2 Administrative measures

  • All Attendae personnel with access to production systems are bound by confidentiality agreements
  • Access to production data is granted on a need-to-know basis and reviewed periodically
  • All significant actions on the platform are logged and attributed to specific users
  • Security and privacy obligations are reviewed at least annually
  • Third-party sub-processors are evaluated and bound by data processing agreements before access is granted

3 Technical measures

  • TLS/HTTPS everywhere: All traffic between users and Attendae is encrypted via TLS. HTTP requests are automatically redirected to HTTPS.
  • Password hashing: User passwords are stored as bcrypt hashes. Plaintext passwords are never stored or logged.
  • Prepared statements (PDO): All database queries use parameterized prepared statements, preventing SQL injection attacks.
  • CSRF protection: Forms and state-changing AJAX requests are protected with per-session CSRF tokens.
  • HttpOnly & Secure cookies: Session cookies cannot be accessed by JavaScript and are transmitted only over HTTPS.
  • Session management: Sessions expire after 2 hours of inactivity and are regenerated every 30 minutes to prevent session fixation.
  • Rate limiting: Login attempts are rate-limited to 5 per 15 minutes per IP address. New account registration is similarly throttled.
  • Input sanitization: All user-supplied input is sanitized and validated before processing or storage.
  • Access audit log: User actions, login events, and administrative operations are recorded in a tamper-evident audit log.
  • Directory listing disabled: Web server directory listing is disabled across all directories.

4 Physical security

Attendae's production infrastructure is hosted on managed server infrastructure operated by our hosting provider (Banahosting). Physical security of the data center — including access controls, surveillance, fire suppression, and environmental controls — is the responsibility of the hosting provider.

Attendae personnel do not have physical access to production server hardware. Administrative access is performed exclusively over encrypted remote connections with key-based authentication.

5 Confidentiality

Attendae treats all institutional data — event records, participant lists, attendance data, and generated certificates — as confidential. This data is not shared with third parties except:

  • As explicitly described in the Privacy Policy (e.g., Stripe for payment processing)
  • When required by a valid legal order from a competent Mexican authority
  • With the express written consent of the Data Controller (the institution)

Attendae does not sell, rent, or commercially exploit institutional or participant data for advertising, research, or any purpose other than providing the contracted service.

6 Incident response

Security incident procedure

In the event of a confirmed security incident affecting personal data, Attendae will:

  • Contain the incident and limit further exposure as quickly as possible
  • Assess the scope, nature, and severity of the incident
  • Notify affected institutions within 72 hours of confirming the breach, where required by law
  • Provide a written incident report including: what happened, data affected, measures taken, and recommended actions for affected institutions
  • Cooperate with INAI and other competent authorities as required
  • Conduct a post-incident review and implement corrective measures

To report a suspected security vulnerability, contact seguridad@attendae.com. We commit to acknowledging all security reports within 5 business days. Responsible disclosure is appreciated and we will not pursue legal action against researchers acting in good faith.

7 Limitations and shared responsibility

No system is 100% secure. While Attendae implements industry-standard security controls, we cannot guarantee absolute security against all possible threats. Security is a shared responsibility.

Institutions using Attendae are responsible for:

  • Maintaining the confidentiality of their administrator account credentials
  • Enabling strong passwords and limiting administrator access to trusted personnel
  • Promptly reporting any suspected unauthorized access to their account
  • Ensuring that participant data they upload (e.g., XLSX files) is handled securely on their own systems before import
  • Complying with applicable data protection laws in their own operations

Attendae's liability for security incidents is limited as described in the Terms of Service and SLA.

8 Security contact

Security issues: seguridad@attendae.com
Privacy & data protection: privacidad@attendae.com
General support: soporte@attendae.com

This policy was last reviewed in 2025 and applies to all Attendae services on attendae.com and attendae.app.

Legal center Terms of Service Privacy Policy Privacy Notice Participant Privacy ARCO Rights Acceptable Use Refund Policy SLA DPA Minor Protection Data Retention Cookie Policy Sub-processors Home Contact 🇲🇽 Versión en español

© 2026 Attendae. All rights reserved.