1 Security principles
Attendae's security program is built on the following principles:
Confidentiality
Personal and institutional data is accessible only to authorized parties with a legitimate need.
Integrity
Data is protected against unauthorized modification, corruption, or deletion.
Availability
Services are designed for high availability as committed in the SLA.
Minimum privilege
Users and processes are granted only the access permissions required for their specific function.
Defense in depth
Multiple overlapping security controls ensure no single point of failure can compromise the system.
2 Administrative measures
- All Attendae personnel with access to production systems are bound by confidentiality agreements
- Access to production data is granted on a need-to-know basis and reviewed periodically
- All significant actions on the platform are logged and attributed to specific users
- Security and privacy obligations are reviewed at least annually
- Third-party sub-processors are evaluated and bound by data processing agreements before access is granted
3 Technical measures
- TLS/HTTPS everywhere: All traffic between users and Attendae is encrypted via TLS. HTTP requests are automatically redirected to HTTPS.
- Password hashing: User passwords are stored as bcrypt hashes. Plaintext passwords are never stored or logged.
- Prepared statements (PDO): All database queries use parameterized prepared statements, preventing SQL injection attacks.
- CSRF protection: Forms and state-changing AJAX requests are protected with per-session CSRF tokens.
- HttpOnly & Secure cookies: Session cookies cannot be accessed by JavaScript and are transmitted only over HTTPS.
- Session management: Sessions expire after 2 hours of inactivity and are regenerated every 30 minutes to prevent session fixation.
- Rate limiting: Login attempts are rate-limited to 5 per 15 minutes per IP address. New account registration is similarly throttled.
- Input sanitization: All user-supplied input is sanitized and validated before processing or storage.
- Access audit log: User actions, login events, and administrative operations are recorded in a tamper-evident audit log.
- Directory listing disabled: Web server directory listing is disabled across all directories.
4 Physical security
Attendae's production infrastructure is hosted on managed server infrastructure operated by our hosting provider (Banahosting). Physical security of the data center — including access controls, surveillance, fire suppression, and environmental controls — is the responsibility of the hosting provider.
Attendae personnel do not have physical access to production server hardware. Administrative access is performed exclusively over encrypted remote connections with key-based authentication.
5 Confidentiality
Attendae treats all institutional data — event records, participant lists, attendance data, and generated certificates — as confidential. This data is not shared with third parties except:
- As explicitly described in the Privacy Policy (e.g., Stripe for payment processing)
- When required by a valid legal order from a competent Mexican authority
- With the express written consent of the Data Controller (the institution)
Attendae does not sell, rent, or commercially exploit institutional or participant data for advertising, research, or any purpose other than providing the contracted service.
6 Incident response
Security incident procedure
In the event of a confirmed security incident affecting personal data, Attendae will:
- Contain the incident and limit further exposure as quickly as possible
- Assess the scope, nature, and severity of the incident
- Notify affected institutions within 72 hours of confirming the breach, where required by law
- Provide a written incident report including: what happened, data affected, measures taken, and recommended actions for affected institutions
- Cooperate with INAI and other competent authorities as required
- Conduct a post-incident review and implement corrective measures
To report a suspected security vulnerability, contact seguridad@attendae.com. We commit to acknowledging all security reports within 5 business days. Responsible disclosure is appreciated and we will not pursue legal action against researchers acting in good faith.
7 Limitations and shared responsibility
No system is 100% secure. While Attendae implements industry-standard security controls, we cannot guarantee absolute security against all possible threats. Security is a shared responsibility.
Institutions using Attendae are responsible for:
- Maintaining the confidentiality of their administrator account credentials
- Enabling strong passwords and limiting administrator access to trusted personnel
- Promptly reporting any suspected unauthorized access to their account
- Ensuring that participant data they upload (e.g., XLSX files) is handled securely on their own systems before import
- Complying with applicable data protection laws in their own operations
Attendae's liability for security incidents is limited as described in the Terms of Service and SLA.