Security & Compliance
This page describes the security controls actually in place at Convene for Good today, our current compliance posture, and the roadmap. We keep it honest — we don't claim certifications we haven't earned.
All traffic is served over TLS 1.2+. Data is stored on managed Postgres with AES-256 encryption at rest.
Every database table is protected by row-level security policies so users can only read and write the data their role permits.
Admin, Member, and Observer roles are enforced server-side. Organizations are capped at three admins to reduce privilege sprawl.
Password sign-in with strength requirements, secure recovery flows, and per-org Zoom OAuth. SAML SSO is available for enterprise plans on request.
Seat changes, invitations, and email deliveries are logged with timestamps so admins can review account activity.
Members can export a full copy of their personal data and delete their account from Settings → Privacy at any time.
Independent SOC 2 examination is planned. We will publish the report and letter here when the audit completes.
HIPAA readiness requires signed Business Associate Agreements with every subprocessor. Not offered today — do not upload PHI.
We are iterating on color contrast, keyboard navigation, focus states, and screen-reader labels across the portal.
Found a security issue? Please email security@conveneforgood.com with details and steps to reproduce. We acknowledge reports within two business days and will not pursue legal action against good-faith researchers.