Slayte hosts submission, conference, and membership data for professional associations and their members. This page describes how we protect it.
The measures on this page are incorporated into our Data Processing Agreement and apply to every Slayte customer.
Last updated: 8/1/27 · Version 2.4

Slayte's software development suite is provided as a service, accessible with just a web browser. We manage operations, hosting, backups, server upgrades, maintenance, and more, simplifying your experience.

Slayte employs AES-256 encryption to secure data at rest, ensuring that stored information is protected by one of the most robust encryption standards available. During data transmission, we utilize TLS 1.2 or higher, which safeguards data integrity and privacy as it travels across networks, preventing unauthorized access and ensuring secure communication.

Slayte leverages Amazon Web Services (AWS) for its hosting needs, specifically utilizing the us-east-1 region. This choice ensures high availability and reliability, as AWS is renowned for its robust infrastructure and comprehensive service offerings. By hosting in the United States, Slayte benefits from AWS's extensive network of data centers, which provide advanced security measures and compliance with industry standards.

We guarantee a 99.5% monthly uptime, supported by service credits to ensure reliability. Our infrastructure is designed to minimize downtime, with redundant systems and proactive monitoring to quickly address any potential issues.

Slayte implements role-based access control to ensure that users have the appropriate permissions for their roles, enhancing security by limiting access to sensitive data. We support Single Sign-On (SSO) to streamline user authentication across multiple applications, reducing the need for multiple passwords and improving security. Additionally, we offer configurable Multi-Factor Authentication (MFA) for administrative access via SSO, adding an extra layer of protection by requiring a second form of verification.

Within 48 hours of confirmation, we initiate our breach notification process. This includes promptly informing affected parties and relevant authorities, as well as providing detailed information about the breach, its impact, and the steps being taken to mitigate any potential damage.

We never store full card numbers, ensuring that sensitive payment information is kept secure. Instead, we use tokenization to replace card details with a unique identifier, which can be used for transactions without exposing the actual card number. This method significantly reduces the risk of data breaches and unauthorized access.

All customer data is encrypted both at rest and in transit, utilizing AES-256 and TLS 1.2 or higher, respectively. This encryption applies universally to primary databases, file storage, and backups. Encryption keys are managed through AWS Key Management Service, with regular rotation to ensure security.
Backups are conducted on an hourly or daily basis for most customer data. These backups are encrypted and kept separate from production environments. Retention of backups is maintained for a period of 90 days, and restoration procedures are tested quarterly to ensure reliability.
In the event of a disaster, defined as the loss or prolonged inaccessibility of Slayte's primary production environment, our objectives are to achieve a recovery point objective (RPO) of four hours and a recovery time objective (RTO) of twenty-four hours. Failures of individual components, such as a server, container, or database replica, which do not qualify as a disaster, are managed through automated failover and redundancy, and are not subject to these objectives.
Slayte personnel are permitted to access Customer Data solely for legitimate business purposes, such as providing requested support or addressing technical issues. All access is meticulously logged. Production access necessitates Multi-Factor Authentication (MFA) and is restricted to a select number of engineers on the platform team.
Slayte's permission model is meticulously designed to align with the operational dynamics of associations. Reviewers are granted access solely to the submissions assigned to them, while committee chairs have visibility over their respective committees. Staff administrators are responsible for system configuration. Permissions are role-based and can be tailored to specific events, calls, or programs. Slayte supports Single Sign-On (SSO) via OAuth 2.0, allowing you to enforce your own password policies, Multi-Factor Authentication (MFA) requirements, and offboarding processes. All Slayte personnel undergo background checks upon hiring and receive annual security awareness training. Access to production systems is granted on a least-privilege basis, reviewed quarterly, and revoked within 24 hours of an employee's departure.


We do not engage in the sale of Customer Data. Furthermore, we refrain from utilizing Customer Data in identifiable form for the purpose of training machine learning or artificial intelligence models that are accessible to other clients. However, we may generate de-identified, aggregated statistics that cannot reasonably be used to identify you, your users, or any individual.
Your data is your property. Slayte processes it solely based on your instructions to deliver the Service, with no other purpose. You can export your data at any time using the Service's export functionality, allowing you to retrieve it without needing our assistance. Upon termination, we retain your data for 30 days, during which you have read-only access to export it. You may instruct us in writing to delete or return all data within this period, and we will comply within 30 days, providing any returned data in a commonly used, machine-readable format. If no instruction is given, we will delete your data within 60 days after the retrieval period ends. Data in routine encrypted backups is isolated from further processing and purged within 90 days of deletion, as part of our backup rotation. We will certify the deletion in writing within 30 days of your request.
Slayte operates on Amazon Web Services within the United States, specifically in the us-east-1 region, ensuring robust infrastructure certified by SOC 2, ISO 27001, and PCI DSS. We guarantee a 99.5% monthly uptime as per our Service Level Agreement, with service credits available for any shortfalls. Customer data is backed up daily, encrypted, and isolated from production environments, with retention and restoration procedures tested regularly. Our disaster recovery plan includes a recovery point objective of a few hours and a recovery time objective of several hours, with detailed targets available upon request. Critical support issues are addressed within two hours during business hours, with comprehensive support available 24/7 via email and tickets, and phone support during standard business hours.


Slayte provides a comprehensive Data Processing Agreement (DPA) that aligns with the jurisdictions where your members reside. Under this agreement, you act as the data controller while Slayte functions as the data processor. In compliance with the California Consumer Privacy Act (CCPA), Slayte operates as a service provider, ensuring that your data is neither sold nor shared as defined by the law. Our DPA encompasses regulations such as the General Data Protection Regulation (GDPR), UK GDPR, Swiss Federal Act on Data Protection (FADP), CCPA, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Brazil's General Data Protection Law (LGPD), and the Australian Privacy Act. Transfers of European personal data are conducted using the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are integrated into the DPA. Regarding payment data, Slayte does not serve as a payment processor or merchant of record. Payments are processed directly through your connected processor account, such as Stripe Connect. Slayte does not receive, store, or process full payment card numbers, only truncated digits and processor-issued tokens, and does not hold or transfer your funds. For data subject requests, the service includes self-service tools to retrieve, correct, delete, and restrict the use of personal data. If these tools are insufficient, we will assist you in responding to requests.
We maintain a publicly accessible list of sub-processors involved in processing Customer Data, detailing their functions and operational locations. Prior to adding or replacing any sub-processor, we will provide a minimum of 30 days' notice. Should you have any concerns based on data protection grounds, you may submit a written objection within 15 days, and we will collaborate with you to address the issue.
Amazon Web Services
What it does: Cloud infrastructure — hosting, compute, and storage for the Slayte platform.
Data processed: All Customer Data.
Location: United States
MongoDB Atlas
What it does: Managed database service holding submissions, event, and membership records.
Data processed: All Customer Data.
Location: United States
Elastic
What it does: Search indexing and application logging.
Data processed: Indexed record content and log data, which may include identifiers such as user IDs and IP addresses.
Location: United States
Sentry
What it does: Application error and performance monitoring.
Data processed: Diagnostic data associated with errors, which may incidentally include identifiers.
Location: United States
Google Workspace
What it does: internal email and documents.
Data processed: All customer data.
Location: United States
Zoho
What it does: Customer support desk. Support conversations between your team and Slayte are handled here.
Data processed: Contact details of your staff, and any information included in a support request.
Location: United States
Retool
What it does: Internal administrative tooling used by Slayte staff to investigate and resolve support issues.
Data processed: Customer Data, where access is required to diagnose a fault. Access is role-restricted, requires a bona fide business purpose, and is logged.
Location: United States


In the event of a confirmed security incident impacting your data, we commit to notifying you within 48 hours. This obligation is enshrined in our Data Processing Agreement and exceeds the 72-hour requirement stipulated by most data protection regulations. Our notification will provide initial details and will be updated as our investigation progresses. We promptly initiate containment and investigation measures. Our incident response plan, which encompasses detection, triage, containment, notification, and post-incident review, is reviewed and tested annually. If you identify a potential security vulnerability in Slayte, please contact us at [email protected]. We strive to acknowledge such reports within five business days and assure that no legal action will be taken against researchers who report in good faith, provided they avoid privacy violations, service degradation, and data destruction.
Our development process incorporates rigorous peer reviews for code changes prior to merging, ensuring quality and compliance with automated testing protocols in our continuous integration pipeline. We diligently monitor dependencies for vulnerabilities, applying critical patches within a ten-day timeframe. Development, staging, and production environments are distinctly separated, with production customer data strictly excluded from development and testing phases. Annually, we engage an independent third party to conduct penetration testing, with summaries available to customers upon request. Infrastructure and application logs are systematically collected and retained for a period of 90 days.
