1. Security approach
Domplatta is designed as a modular event-operations platform in which access, data movement and operator actions can be controlled at the event and module level. Security depends on both the platform configuration and the hosting, identity, device and operational practices selected for each deployment.
This page is a public overview, not a certification, penetration-test report or guarantee that every customer environment uses every control described.
2. Identity and access control
- Role and capability checks for administrative, API and frontend operations.
- Scoped access for event teams, organizations, exhibitors, sponsors and session operators.
- Administrator recovery and diagnostic controls intended to prevent accidental lockout.
- Least-privilege configuration for desks, kiosks, badge operators, reporting users and external teams.
Customers are responsible for maintaining accurate user assignments, protecting credentials, removing departed users and reviewing privileged access.
3. Application and integration controls
- Input validation, permission checks and request-specific authorization.
- Nonce or equivalent request-protection mechanisms for privileged browser actions.
- Signed webhook intake, idempotency controls and queued delivery for supported integrations.
- Import validation, row-level errors, rollback records and operational diagnostics.
- Rate limiting and anti-bot controls for the public contact form.
Integration secrets should be stored in protected configuration or environment storage and should never be committed to public repositories or included in distributable website packages.
4. Logging and accountability
Domplatta can record important operational actions with event, actor, object and source context. Depending on the enabled modules, this may include attendee updates, check-ins, badge printing, lead activity, session changes, organization changes, exports and integration operations.
Logs should be restricted to authorized users, retained for a defined period and reviewed in proportion to the risk and support needs of the event.
5. Hosting, transmission and backups
Production deployments should use HTTPS, supported server software, protected administrative access, restricted configuration files, monitored storage and tested backups. Backup frequency and recovery objectives are agreed according to the event scale and hosting arrangement.
Domplatta does not claim that presentation-site source files alone provide a complete production security environment. Hosting and operational procedures are part of the security boundary.
6. Security incidents
Suspected unauthorized access, data disclosure, malware, credential compromise or material service disruption should be reported promptly through the Contact panel. Include the affected URL or event, time observed, reproduction steps and a safe description of the issue.
Please do not access, modify, download or disclose other people’s data while investigating a suspected issue. There is no public bug-bounty commitment unless one is agreed separately in writing.
7. Maintenance and responsibility
Security maintenance includes reviewing updates, testing changes, limiting exposed services, protecting administrator accounts and checking that event devices remain under authorized control. Customers and delivery partners must follow the agreed operating procedures and report lost devices or compromised credentials without delay.