Security & Compliance

What we protect, and how.

This page describes the security controls actually in place at Convene for Good today, our current compliance posture, and the roadmap. We keep it honest — we don't claim certifications we haven't earned.

In place today

Encryption in transit & at rest

All traffic is served over TLS 1.2+. Data is stored on managed Postgres with AES-256 encryption at rest.

Row-level access control

Every database table is protected by row-level security policies so users can only read and write the data their role permits.

Role-based permissions

Admin, Member, and Observer roles are enforced server-side. Organizations are capped at three admins to reduce privilege sprawl.

Modern authentication

Password sign-in with strength requirements, secure recovery flows, and per-org Zoom OAuth. SAML SSO is available for enterprise plans on request.

Audit trail

Seat changes, invitations, and email deliveries are logged with timestamps so admins can review account activity.

GDPR user rights

Members can export a full copy of their personal data and delete their account from Settings → Privacy at any time.

Compliance roadmap

On roadmap

SOC 2 Type II

Independent SOC 2 examination is planned. We will publish the report and letter here when the audit completes.

On roadmap

HIPAA

HIPAA readiness requires signed Business Associate Agreements with every subprocessor. Not offered today — do not upload PHI.

In progress

WCAG 2.1 AA

We are iterating on color contrast, keyboard navigation, focus states, and screen-reader labels across the portal.

Report a vulnerability

Found a security issue? Please email security@conveneforgood.com with details and steps to reproduce. We acknowledge reports within two business days and will not pursue legal action against good-faith researchers.