Security

Security-first operations for trustworthy conference delivery.

vCongress combines modern account protection, strict role separation, and operational traceability for conference teams handling sensitive participant and submission data.

Data residency

Where your data lives

The first question a German research institution asks, answered before the architecture.

Hosting regionAWS eu-central-1 — Frankfurt am Main, Germany.
Where participant data is processedIn the EU. Participant records, submissions, uploads, and invoices are processed in the hosting region.
The one exception, and it is opt-inThree optional AI capabilities — drafting an abstract from an uploaded PDF, bulk normalisation of participant and submission fields, and the in-app help assistant — send the text being processed to Google's Gemini API. All three are off unless you ask us to enable them for your organisation, and nothing is sent until they are on.
Tenant separationEvery record is scoped to its organisation and event; access is resolved per request against the signed-in identity.
Your own identity providerOptional tenant OIDC/SSO, so accounts stay governed by your directory rather than by us.
Who else touches the dataThe list is short and we name it: AWS for hosting and storage in Frankfurt, with outbound mail delivered through AWS SES in Ireland; the payment provider you choose per event (Stripe or PayPal); and Google's Gemini API only where you have switched the optional AI features on. No web analytics, no advertising or tracking services, no data brokers — this site runs none either.

Need the data-processing agreement, the subprocessor list, or a security questionnaire completed for procurement? Ask us and we will send them.

Security pillars

Identity hardening

Passkey-capable authentication, tenant OIDC/SSO, and account-security controls reduce phishing and password risk.

Role-scoped access

Organizer, employee, admin, and participant scopes keep sensitive actions constrained to intended users.

Action traceability

Notification and domain-event visibility supports investigations, quality control, and process governance.

Public/app isolation

Public marketing frontend is separated from authenticated app runtime to reduce exposure.

Safer communication controls

Recipient preview before notification dispatch helps prevent broad targeting mistakes.

Controlled financial actions

Invoice reminders, refunds, and cancellation flows are explicit platform actions with clear user context.

Tenant-owned identity configuration

Enterprise OIDC connections use tenant-specific issuers, safe secret references, claim mapping, and role allowlisting.

Participant access policy

Events can be configured for local registration, optional SSO, required SSO, or invite-only access.

Enterprise SSO without broad trust shortcuts

OIDC compatibility

vCongress supports standards-compliant OIDC discovery flows with HTTPS issuers, including Microsoft Entra ID and Keycloak-compatible providers.

Controlled role propagation

External roles are mapped or allowlisted before they become vCongress roles. Administrative roles are not blindly accepted from an identity provider.

Clear SAML boundary

SAML is not presented as existing OIDC compatibility. If required, it is scoped as a separate enterprise identity integration.

Operational audit visibility

Real-time event and action timelines help teams investigate issues faster and keep critical workflows transparent across organizer roles.

Deployment architecture benefits