Trust Center

Trust CenterSecurity, privacy and compliance in one place.

Attendee data is personal data. AirLST is TISAX-assessed, processes data under the GDPR with a data processing agreement and runs on Amazon Web Services in Germany. Here are the credentials and how to get the documents for your vendor review.

01Credentials

What is proven, and by whom

AirLST itself is TISAX-assessed. The data center certifications belong to our hosting provider AWS; we list them because your IT team asks, not as our own.

The AWS credentials cover the infrastructure (data centers, network, virtualization), not the AirLST application. Current status: AWS compliance programs.

03Documents

Documents for your vendor review

What procurement and privacy teams usually ask for, and how you get it.

  1. 01

    Data processing agreement (DPA)

    Under GDPR Article 28, provided during contracting. It covers instructions, confidentiality and technical and organizational measures.

  2. 02

    Subprocessor list

    With the DPA, always current. More on the subprocessors page.

  3. 03

    TISAX result

    Shared through the ENX Association portal; we agree the release with you. More on the TISAX page.

  4. 04

    Security questionnaires

    We answer questionnaires from your procurement or IT security team; send them to kontakt@airlst.com.

  5. 05

    Service levels

    Availability and service levels are agreed in the contract.

04Customers

Reviewed by demanding procurement teams

Companies in automotive, retail and aviation run their attendee management on AirLST. See the customer stories for details.

Trusted by
Mercedes-BenzAudiBMWZalandoAmazonMunich AirportHeineken
05FAQ

Trust center FAQ

What is the purpose of a trust center?

A trust center collects a vendor's security, privacy and compliance information in one place, so procurement, IT security and privacy teams can review it before they sign. The AirLST trust center covers the TISAX assessment, GDPR compliance, hosting in Germany and subprocessors.

Which security credentials can AirLST provide?

AirLST is TISAX-assessed, the information security standard of the automotive industry; the result is shared through the ENX Association portal. The infrastructure of our hosting provider Amazon Web Services holds ISO/IEC 27001, SOC 2 and BSI C5. Those are AWS credentials, not AirLST certifications. AirLST does not have its own SOC 2 report.

Where is AirLST data hosted?

On Amazon Web Services in Germany. What that means for data residency and your contract is described on the data hosting page.

Is AirLST GDPR compliant?

Yes. AirLST processes attendee data under the GDPR, hosted in Germany. The organizer stays the controller, AirLST is the processor, and a data processing agreement (DPA) governs the relationship; details on the GDPR page.

How do I get the list of subprocessors?

You receive the current list with the data processing agreement or on request at kontakt@airlst.com. The subprocessors page explains the background.

Are service levels part of the contract?

Yes. Availability and service levels are agreed in the contract; we discuss the figures for your project during contracting.

Who answers security questions during procurement?

Send questions from procurement, IT security or privacy to kontakt@airlst.com or use the contact form; we answer security questionnaires. To see roles and data in the product, book a meeting.
Events made easy

Security questions? We answer at the product.

In 15 minutes we answer the questions of your procurement, IT and privacy teams, right in the platform.