1. Encryption in transit
All traffic to and from submitcfp is encrypted using industry-standard HTTPS/TLS, so data moving between your browser and our servers is protected.
2. Secure hosting
Application data is stored in a managed, access-controlled cloud database. Our infrastructure providers maintain strong physical and network security and recognized compliance certifications.
3. Authentication
Passwords are never stored in plain text — they are salted and hashed using a strong, industry-standard algorithm. Sessions are protected with signed tokens, and access to your data requires authentication.
4. Access controls
The platform enforces role-based access — organizers, co-organizers, reviewers and speakers each see only the data appropriate to their role. Blind-review mode and stage isolation further protect submission and reviewer data.
5. Payment security
Payments, when applicable, are handled entirely by PCI-DSS-compliant processors (Stripe and/or Razorpay). submitcfp does not store or process your full card number.
6. Responsible disclosure
If you believe you have found a security vulnerability, please report it privately to contact@submitcfp.com with enough detail to reproduce it. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We appreciate the security community’s help in keeping submitcfp safe.
7. Incident response
We monitor for suspicious activity and maintain procedures to investigate and respond to incidents. In the event of a data breach affecting your personal data, we will notify affected users and relevant authorities as required by law.
8. Your role
You help keep your account secure by using a strong, unique password and keeping your credentials private. If you suspect any unauthorized access, contact us immediately at contact@submitcfp.com.
