Event data securityHow AirLST protects attendee data.
Guest lists hold names, contact details and often travel or hotel data. AirLST treats protecting them as a baseline requirement for platform and organization, and has its information security independently assessed under TISAX, the standard of the automotive industry.
Three documented foundations for your review
What procurement and IT security ask first about an event platform, and where the answer comes from.
TISAX-assessed
AirLST's information security is assessed under TISAX. The result is shared with business partners through the ENX Association portal. More on the TISAX page.
Source: ENX Association: TISAXHosted on AWS in Germany
The platform runs on Amazon Web Services in Germany. The AWS infrastructure holds ISO/IEC 27001, SOC 2 and BSI C5; those are credentials of the hosting provider, not of AirLST.
Source: AWS compliance programsGDPR with a DPA
The organizer stays the controller, AirLST processes on its behalf. A data processing agreement under GDPR Article 28 governs the relationship. More on the GDPR page.
Source: GDPR Article 28Security you see in daily work
Beyond the credentials, what matters is what happens inside the event: who sees which data and what stays traceable.
- Roles and permissionsRoles and permissions decide who can see and change what, for example project lead, check-in team and agency. More in the guest list.
- Encrypted in transitWebsite, registration flows and platform are served over HTTPS only.
- Change logEvery change to a guest is recorded with time, field, old and new value.
- Scanning without guest dataExternal teams scanning for lead retrieval can work in "No guest data" mode and only see green or red, no names.
Technical and organizational measures in detail (encryption, backups, disaster recovery) come with the DPA or on request at kontakt@airlst.com.


