Trust CenterSecurity, privacy and compliance in one place.
Attendee data is personal data. AirLST is TISAX-assessed, processes data under the GDPR with a data processing agreement and runs on Amazon Web Services in Germany. Here are the credentials and how to get the documents for your vendor review.
What is proven, and by whom
AirLST itself is TISAX-assessed. The data center certifications belong to our hosting provider AWS; we list them because your IT team asks, not as our own.
TISAX-assessedAirLST itself is assessed under TISAX, the security standard of the automotive industry.ISO/IEC 27001 data centersHeld by our hosting provider AWS for its infrastructure, alongside SOC 2 and BSI C5.
GDPRProcessing under the GDPR, with a data processing agreement and hosting in Germany.
Encrypted in transitWebsite, registration and platform are delivered over HTTPS only.
The AWS credentials cover the infrastructure (data centers, network, virtualization), not the AirLST application. Current status: AWS compliance programs.
What the trust center covers
Each page answers one question from a vendor security review, with evidence and a contact.
Documents for your vendor review
What procurement and privacy teams usually ask for, and how you get it.
- 01
Data processing agreement (DPA)
Under GDPR Article 28, provided during contracting. It covers instructions, confidentiality and technical and organizational measures.
- 02
Subprocessor list
With the DPA, always current. More on the subprocessors page.
- 03
TISAX result
Shared through the ENX Association portal; we agree the release with you. More on the TISAX page.
- 04
Security questionnaires
We answer questionnaires from your procurement or IT security team; send them to kontakt@airlst.com.
- 05
Service levels
Availability and service levels are agreed in the contract.
Reviewed by demanding procurement teams
Companies in automotive, retail and aviation run their attendee management on AirLST. See the customer stories for details.







