Trust Center

Event data securityHow AirLST protects attendee data.

Guest lists hold names, contact details and often travel or hotel data. AirLST treats protecting them as a baseline requirement for platform and organization, and has its information security independently assessed under TISAX, the standard of the automotive industry.

01Foundations

Three documented foundations for your review

What procurement and IT security ask first about an event platform, and where the answer comes from.

01

TISAX-assessed

AirLST's information security is assessed under TISAX. The result is shared with business partners through the ENX Association portal. More on the TISAX page.

Source: ENX Association: TISAX
02

Hosted on AWS in Germany

The platform runs on Amazon Web Services in Germany. The AWS infrastructure holds ISO/IEC 27001, SOC 2 and BSI C5; those are credentials of the hosting provider, not of AirLST.

Source: AWS compliance programs
03

GDPR with a DPA

The organizer stays the controller, AirLST processes on its behalf. A data processing agreement under GDPR Article 28 governs the relationship. More on the GDPR page.

Source: GDPR Article 28
02In the platform

Security you see in daily work

Beyond the credentials, what matters is what happens inside the event: who sees which data and what stays traceable.

  • Roles and permissionsRoles and permissions decide who can see and change what, for example project lead, check-in team and agency. More in the guest list.
  • Encrypted in transitWebsite, registration flows and platform are served over HTTPS only.
  • Change logEvery change to a guest is recorded with time, field, old and new value.
  • Scanning without guest dataExternal teams scanning for lead retrieval can work in "No guest data" mode and only see green or red, no names.

Technical and organizational measures in detail (encryption, backups, disaster recovery) come with the DPA or on request at kontakt@airlst.com.

04FAQ

Event data security FAQ

What does event data security mean for an event platform?

It means protecting the personal data that flows through registration, guest lists and on-site check-in: names, contact details and often travel or hotel information. For AirLST that rests on an externally assessed information security program (TISAX), processing under the GDPR and hosting on Amazon Web Services in Germany.

Is AirLST ISO 27001 or SOC 2 certified?

No. AirLST does not hold its own ISO 27001 certification or SOC 2 report; its external evidence is the TISAX assessment. The platform runs on Amazon Web Services, whose infrastructure is certified to ISO/IEC 27001 and covered by SOC 1, SOC 2 and SOC 3 reports; see data hosting.

Is attendee data encrypted in transit?

Yes. The website, registration flows and the platform are served over HTTPS only. Details on encryption, backups and disaster recovery come with the technical and organizational measures of the DPA or on request.

Why does a TISAX assessment matter if we are not in the automotive industry?

TISAX is carried out by independent audit providers and covers how a company handles confidential information across the organization. That evidence carries over to security reviews in any industry. More on the TISAX page.

How can our procurement team request security documentation?

Send your request, including security questionnaires, to kontakt@airlst.com or through the contact form. The data processing agreement comes with contracting; see GDPR.
Events made easy

Your IT security team has questions?

In 15 minutes we show how AirLST processes attendee data and answer the questions of your security and privacy leads.