Security at Seamless

    Your event data - speakers, schedules, attendees, content - is the core of what you trust us with. Here is exactly how we protect it, in plain terms.


    Infrastructure

    Seamless runs entirely on managed, security-hardened cloud infrastructure - we operate no raw servers, and production is fully isolated from our beta environment.

    Google Cloud

    The API runs on Cloud Run - patched, auto-scaling containers with TLS enforced on every request. The app and this website are served by Firebase Hosting.

    CockroachDB

    Your data lives in a distributed SQL database with a dedicated production cluster, fully separate from our staging database.

    Cloudflare

    The website and API are served through Cloudflare's global network, which absorbs DDoS traffic before it reaches us.

    Your data, protected

    Encrypted in transit and at rest

    All traffic is TLS-encrypted. The database is encrypted at rest, and credentials for connected integrations are additionally encrypted before they are ever stored.

    Located in the EU

    Our primary data stores run in Belgium (Google Cloud, CockroachDB) and Western Europe (Cloudflare R2, where event files live).

    Backed up automatically

    Daily full database backups with 30-day retention, managed automatically by CockroachDB Cloud.

    Kept to a minimum

    We only process the attendee and event data you enter, on your behalf - we don't sell it, share it, or use it for anything else.

    Access & authentication

    No passwords on our servers

    Sign in with Google, Microsoft, or email - authentication is handled entirely by Firebase Authentication (Google's identity infrastructure). Passwords never reach our systems.

    Signed, authenticated sessions

    Every API request carries a signed token, checked against your role and permissions before any data moves.

    Role-based access control

    Built into the product: organization admins and editors with fine-grained, per-capability permissions, enforced on every API request.

    Payments that never touch our servers

    Checkout and payments are handled by Polar (our merchant of record) and Stripe for organizer payouts. Card numbers are entered on their compliant checkout pages - they are never stored on or transmitted through Seamless infrastructure.

    You stay in control

    • Delete your account yourself, anytime, from account settings - no support ticket required.

    • Data processed on your behalf - you remain in control of your data and can request deletion at any time, as described in our Privacy Policy.

    Subprocessors

    These providers process data as part of delivering the service:

    ProviderPurpose
    Google Cloud (Firebase)Application hosting, authentication
    Cockroach LabsPrimary database (EU region)
    CloudflareCDN & DDoS protection, event file storage, DNS
    PolarPayments - merchant of record
    StripeOrganizer payouts (Stripe Connect)
    BrevoTransactional email
    MicrosoftSign-in provider

    Report a vulnerability

    If you've found a security issue, please tell us: email security@seamlessevents.io and we'll acknowledge your report and act on it. We'd rather hear from you than find out the hard way.

    Questions about data protection or privacy? Contact us - see also our Privacy Policy, Terms & Conditions, and Cookie Policy.

    We use cookies to improve your experience. Do you consent to analytics tracking?