Security at Slayte

Slayte hosts submission, conference, and membership data for professional associations and their members. This page describes how we protect it.

The measures on this page are incorporated into our Data Processing Agreement and apply to every Slayte customer.

Last updated: 8/1/27 · Version 2.4

Schedule Demo

At a glance

Slayte's software development suite is provided as a service, accessible with just a web browser. We manage operations, hosting, backups, server upgrades, maintenance, and more, simplifying your experience.

Encryption

Slayte employs AES-256 encryption to secure data at rest, ensuring that stored information is protected by one of the most robust encryption standards available. During data transmission, we utilize TLS 1.2 or higher, which safeguards data integrity and privacy as it travels across networks, preventing unauthorized access and ensuring secure communication.

Hosting

Slayte leverages Amazon Web Services (AWS) for its hosting needs, specifically utilizing the us-east-1 region. This choice ensures high availability and reliability, as AWS is renowned for its robust infrastructure and comprehensive service offerings. By hosting in the United States, Slayte benefits from AWS's extensive network of data centers, which provide advanced security measures and compliance with industry standards.

Availability

We guarantee a 99.5% monthly uptime, supported by service credits to ensure reliability. Our infrastructure is designed to minimize downtime, with redundant systems and proactive monitoring to quickly address any potential issues.

Access control

Slayte implements role-based access control to ensure that users have the appropriate permissions for their roles, enhancing security by limiting access to sensitive data. We support Single Sign-On (SSO) to streamline user authentication across multiple applications, reducing the need for multiple passwords and improving security. Additionally, we offer configurable Multi-Factor Authentication (MFA) for administrative access via SSO, adding an extra layer of protection by requiring a second form of verification.

Breach notification

Within 48 hours of confirmation, we initiate our breach notification process. This includes promptly informing affected parties and relevant authorities, as well as providing detailed information about the breach, its impact, and the steps being taken to mitigate any potential damage.

Payment data

We never store full card numbers, ensuring that sensitive payment information is kept secure. Instead, we use tokenization to replace card details with a unique identifier, which can be used for transactions without exposing the actual card number. This method significantly reduces the risk of data breaches and unauthorized access.

Data protection & encryption

All customer data is encrypted both at rest and in transit, utilizing AES-256 and TLS 1.2 or higher, respectively. This encryption applies universally to primary databases, file storage, and backups. Encryption keys are managed through AWS Key Management Service, with regular rotation to ensure security.

Backups are conducted on an hourly or daily basis for most customer data. These backups are encrypted and kept separate from production environments. Retention of backups is maintained for a period of 90 days, and restoration procedures are tested quarterly to ensure reliability.

In the event of a disaster, defined as the loss or prolonged inaccessibility of Slayte's primary production environment, our objectives are to achieve a recovery point objective (RPO) of four hours and a recovery time objective (RTO) of twenty-four hours. Failures of individual components, such as a server, container, or database replica, which do not qualify as a disaster, are managed through automated failover and redundancy, and are not subject to these objectives.

Access Control

Slayte personnel are permitted to access Customer Data solely for legitimate business purposes, such as providing requested support or addressing technical issues. All access is meticulously logged. Production access necessitates Multi-Factor Authentication (MFA) and is restricted to a select number of engineers on the platform team.

Slayte's permission model is meticulously designed to align with the operational dynamics of associations. Reviewers are granted access solely to the submissions assigned to them, while committee chairs have visibility over their respective committees. Staff administrators are responsible for system configuration. Permissions are role-based and can be tailored to specific events, calls, or programs. Slayte supports Single Sign-On (SSO) via OAuth 2.0, allowing you to enforce your own password policies, Multi-Factor Authentication (MFA) requirements, and offboarding processes. All Slayte personnel undergo background checks upon hiring and receive annual security awareness training. Access to production systems is granted on a least-privilege basis, reviewed quarterly, and revoked within 24 hours of an employee's departure.

Your Data

We do not engage in the sale of Customer Data. Furthermore, we refrain from utilizing Customer Data in identifiable form for the purpose of training machine learning or artificial intelligence models that are accessible to other clients. However, we may generate de-identified, aggregated statistics that cannot reasonably be used to identify you, your users, or any individual.

Your data is your property. Slayte processes it solely based on your instructions to deliver the Service, with no other purpose. You can export your data at any time using the Service's export functionality, allowing you to retrieve it without needing our assistance. Upon termination, we retain your data for 30 days, during which you have read-only access to export it. You may instruct us in writing to delete or return all data within this period, and we will comply within 30 days, providing any returned data in a commonly used, machine-readable format. If no instruction is given, we will delete your data within 60 days after the retrieval period ends. Data in routine encrypted backups is isolated from further processing and purged within 90 days of deletion, as part of our backup rotation. We will certify the deletion in writing within 30 days of your request.

Access control & authentication

Slayte operates on Amazon Web Services within the United States, specifically in the us-east-1 region, ensuring robust infrastructure certified by SOC 2, ISO 27001, and PCI DSS. We guarantee a 99.5% monthly uptime as per our Service Level Agreement, with service credits available for any shortfalls. Customer data is backed up daily, encrypted, and isolated from production environments, with retention and restoration procedures tested regularly. Our disaster recovery plan includes a recovery point objective of a few hours and a recovery time objective of several hours, with detailed targets available upon request. Critical support issues are addressed within two hours during business hours, with comprehensive support available 24/7 via email and tickets, and phone support during standard business hours.

Privacy & regulatory

Slayte provides a comprehensive Data Processing Agreement (DPA) that aligns with the jurisdictions where your members reside. Under this agreement, you act as the data controller while Slayte functions as the data processor. In compliance with the California Consumer Privacy Act (CCPA), Slayte operates as a service provider, ensuring that your data is neither sold nor shared as defined by the law. Our DPA encompasses regulations such as the General Data Protection Regulation (GDPR), UK GDPR, Swiss Federal Act on Data Protection (FADP), CCPA, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Brazil's General Data Protection Law (LGPD), and the Australian Privacy Act. Transfers of European personal data are conducted using the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are integrated into the DPA. Regarding payment data, Slayte does not serve as a payment processor or merchant of record. Payments are processed directly through your connected processor account, such as Stripe Connect. Slayte does not receive, store, or process full payment card numbers, only truncated digits and processor-issued tokens, and does not hold or transfer your funds. For data subject requests, the service includes self-service tools to retrieve, correct, delete, and restrict the use of personal data. If these tools are insufficient, we will assist you in responding to requests.

Sub-processors

We maintain a publicly accessible list of sub-processors involved in processing Customer Data, detailing their functions and operational locations. Prior to adding or replacing any sub-processor, we will provide a minimum of 30 days' notice. Should you have any concerns based on data protection grounds, you may submit a written objection within 15 days, and we will collaborate with you to address the issue.

Amazon Web Services
What it does: Cloud infrastructure — hosting, compute, and storage for the Slayte platform.
Data processed: All Customer Data.
Location: United States

MongoDB Atlas

What it does: Managed database service holding submissions, event, and membership records.

Data processed: All Customer Data.

Location: United States

Elastic

What it does: Search indexing and application logging.

Data processed: Indexed record content and log data, which may include identifiers such as user IDs and IP addresses.

Location: United States

Sentry

What it does: Application error and performance monitoring.

Data processed: Diagnostic data associated with errors, which may incidentally include identifiers.

Location: United States

Google Workspace

What it does: internal email and documents.

Data processed: All customer data.

Location: United States

Zoho

What it does: Customer support desk. Support conversations between your team and Slayte are handled here.

Data processed: Contact details of your staff, and any information included in a support request.

Location: United States

Retool

What it does: Internal administrative tooling used by Slayte staff to investigate and resolve support issues.

Data processed: Customer Data, where access is required to diagnose a fault. Access is role-restricted, requires a bona fide business purpose, and is logged.

Location: United States

Incident Response

In the event of a confirmed security incident impacting your data, we commit to notifying you within 48 hours. This obligation is enshrined in our Data Processing Agreement and exceeds the 72-hour requirement stipulated by most data protection regulations. Our notification will provide initial details and will be updated as our investigation progresses. We promptly initiate containment and investigation measures. Our incident response plan, which encompasses detection, triage, containment, notification, and post-incident review, is reviewed and tested annually. If you identify a potential security vulnerability in Slayte, please contact us at [email protected]. We strive to acknowledge such reports within five business days and assure that no legal action will be taken against researchers who report in good faith, provided they avoid privacy violations, service degradation, and data destruction.

Secure Development

Our development process incorporates rigorous peer reviews for code changes prior to merging, ensuring quality and compliance with automated testing protocols in our continuous integration pipeline. We diligently monitor dependencies for vulnerabilities, applying critical patches within a ten-day timeframe. Development, staging, and production environments are distinctly separated, with production customer data strictly excluded from development and testing phases. Annually, we engage an independent third party to conduct penetration testing, with summaries available to customers upon request. Infrastructure and application logs are systematically collected and retained for a period of 90 days.

Experience the Future of Association Management
Join the growing number of organizations using Slayte to power seamless events and their association engagement programs. Whether you're planning a small conference or a large-scale event, we're here to help you succeed and thrive as a member-based organization.