Security & Privacy
Last updated: July 2026

Security at Event Registration Hub

How we protect participant data, payments, hotel bookings, and manager access — with modern encryption, strong authentication, and clear operational controls.

Download Security Overview PDFPDF version 2026.07 · Automatically generated from current platform configuration
Security Highlights
The core protections built into every account.
HTTPS / TLS Encryption
Role-Based Access Control
Row Level Security (RLS)
Two-Factor Authentication
Secure Hosted Payments
Login History & Sessions
Account Lockout Protection
Payment & Email Logging
Overview

Event Registration Hub securely manages event registrations, participant data, hotel bookings, payments, emails, and manager access. This page summarizes the security and privacy controls that protect that information.

Platform Overview
Who builds and operates Event Registration Hub.

Event Registration Hub is independently designed, developed, maintained and operated in-house by Rami Madgar Laor.

Customers such as Eshet Incoming, JDC and other organizations use the platform for event registration, hotel bookings, payments and participant communication.

Architecture
How participant data travels across the platform.
Participant
HTTPS / TLS
Event Registration Hub
Vercel hosting
Supabase
Authentication
Database
Storage
Resend
Transactional email
Pelecard
Hosted payments
Optional
Customer Back Office API
e.g. receipt creation
Security Features
A snapshot of what's active on the platform today.
FeatureStatus
HTTPS / TLSAvailable
Role-Based Access ControlAvailable
Row Level SecurityAvailable
Two-Factor AuthenticationAvailable
Login HistoryAvailable
Active SessionsAvailable
Account LockoutAvailable
Hosted PaymentsAvailable
Payment LoggingAvailable
Email LoggingAvailable
Data Protection
  • HTTPS/TLS encryption for all data in transit
  • Supabase-managed PostgreSQL database
  • Row Level Security (RLS) enforced on application tables
  • Role-based access control (admin / manager / user)
  • Managers can only access forms explicitly assigned to them
  • Service role keys are used only server-side and never shipped to the browser
Authentication & Access
  • Authentication powered by Supabase Auth
  • JWT-based sessions
  • Optional two-factor authentication, with required 2FA for admin/manager roles when enabled
  • TOTP authenticator app support (Google Authenticator, Microsoft Authenticator, etc.)
  • TOTP secrets encrypted at rest using AES-256-GCM
  • Account lockout after configurable failed login attempts
  • Dynamic inactivity logout based on configured session timeout
  • Active session tracking with the ability to revoke individual sessions
  • Login history recorded for admin review
How Your Data Is Protected
The path a registration takes from browser to database.
Registration
Participant submits form
Encrypted HTTPS
TLS in transit
Supabase Database
Managed PostgreSQL
Role-Based Access Control
RLS + role checks
Authorized Users Only
Admins & assigned managers
Optional Hosted Payment
Pelecard hosted checkout
Payment Security
  • Credit card data is never stored by Event Registration Hub
  • All card entry happens through Pelecard hosted checkout
  • Payment results are verified server-side before a registration is marked paid
  • Payment transactions, receipts, and sync logs are stored securely
  • Payment API credentials are never exposed to managers or public users
Email Security
  • Transactional emails are sent through Resend
  • Verified sending domain
  • SPF, DKIM, and DMARC support for domain authentication
  • Confirmation and payment email delivery is logged
Privacy Controls
  • Sensitive fields are not included in emails unless explicitly selected by the form owner
  • Managers only see the forms assigned to them
  • Receipt, debug, and payment gateway logs are restricted to admins
  • Cancellation policy and privacy policy acceptance can be tracked per registration
Monitoring
  • Login history
  • Active sessions
  • Failed login tracking
  • Account lockout
  • Payment logs
  • Email logs
  • Receipt sync logs
Data Retention
How long data is retained on the platform.
Registration Data

Up to 12 months after the event, unless otherwise requested by the organizer.

Payment Records

Retained in accordance with applicable accounting and legal obligations.

Business Continuity
Operational resilience of the platform.
  • Managed cloud infrastructure
  • Automatic Supabase backups
  • Vercel hosting
  • Continuous monitoring
Incident Response
The process followed when a security incident is detected.
1. Detection
Continuous monitoring of infrastructure, logs and platform activity.
2. Containment
Isolate affected systems and limit impact.
3. Investigation
Root cause analysis, scope determination and evidence gathering.
4. Customer Notification
Affected customers are notified with relevant facts and timelines.
5. Resolution
Fix deployment, verification and restoration of normal service.
6. Post-Incident Review
Lessons learned and follow-up improvements.
Data Residency
Where customer data lives and how it's protected.

Customer data is stored within the configured Supabase project region. Application traffic is encrypted using HTTPS/TLS. Managed infrastructure provides encryption at rest for stored data.

Security Principles
The values that guide how we design and operate the platform.
Least Privilege Access
Role-Based Permissions
Defense in Depth
Secure Hosted Payments
Row Level Security
Continuous Security Improvements
Continuous Security Improvements
Security is an ongoing program. Current focus areas:
Comprehensive Administrative Audit Log
In progress
Application-Level Encryption for Sensitive Fields
In progress
GDPR Self-Service Tools
In progress
Administrator Security Dashboard
In progress
Built With Trusted Technologies
Established providers that power the platform.
Vercel
Application hosting & global edge network
Supabase
Authentication, PostgreSQL database & storage
Resend
Transactional email delivery
Pelecard
Hosted payment processing
Frequently Asked Questions
Quick answers to common security questions.

Important note on certifications
Please read our current certification status.

Event Registration Hub is not currently ISO 27001, SOC 2, HIPAA, or PCI-DSS certified as a platform. Payment card processing is handled by Pelecard hosted checkout, and Event Registration Hub does not store card data.

Security contact

To report a security concern or ask a question about our security practices, contact us at info@eventreghub.com.

← Back to homeLast updated: July 2026