Security at Hallway
Last updated: 3 September 2026
Contact: hello@hallway.events
This page describes the security measures Hallway actually runs. Hallway is a product of Venn Labs LLC, a small independent company; we do not currently hold SOC 2 or ISO 27001 certification, and we would rather tell you precisely what we do than imply a posture we have not audited. The commitments below are the same ones we make contractually in our Data Processing Addendum.
Hosting and architecture
- Production runs on Railway in the United States (us-west2 region), with object storage on Cloudflare R2, also in the United States.
- Participant data is hosted only in the United States; the full list of sub-processors that can touch participant data, and what each receives, is in our DPA.
- Backups are encrypted and expire on a routine 30-day cycle.
Data in transit and at rest
- All traffic is encrypted in transit with TLS.
- Passwords and other secrets are stored only as salted hashes, never in readable form.
- Authentication uses signed, HTTP-only session cookies.
Access controls
- Role-based access controls limit who can see participant data.
- Sensitive fields - such as dietary requirements and accessibility needs - default to a private visibility tier, are never public, and are masked in the interface until a permitted user chooses to reveal them.
- Travel and contact details are never made publicly visible.
Monitoring and abuse prevention
- Rate limiting and abuse detection (Arcjet) protect the service's endpoints.
- Error monitoring (Sentry) receives diagnostic reports that are scrubbed before transmission: request bodies, cookies, query strings, and IP and email addresses are removed.
- Application, security, and LLM-call logs are rotated automatically and deleted after 90 days.
Incident response
If we become aware of a security incident affecting an organiser's participant data, we notify the affected organiser without undue delay, and in any event within 72 hours of becoming aware of it, with the detail set out in our DPA.
Data lifecycle
- Participant data is deleted within 30 days of an organiser's termination or written request, with a machine-readable export available on request first.
- We do not sell personal data and do not use participant data to train, fine-tune, or otherwise modify any AI model.
Reporting a vulnerability
If you believe you have found a security vulnerability in Hallway, please email hello@hallway.events with enough detail to reproduce it. We will acknowledge your report promptly, keep you informed as we investigate, and will not take legal action against good-faith research that respects user data and avoids service disruption.