CommTrail, LLC

Sheridan, Wyoming 82801

legal@commtrail.com

April 16, 2026

To Whom It May Concern,

I am writing on behalf of CommTrail, LLC, the developer and operator of Meeting Signup (signup.commtrail.com), to provide this security attestation letter for use in vendor assessment and procurement processes.

CommTrail, LLC is a Wyoming limited liability company providing a Software-as-a-Service platform that enables government agencies, educational institutions, homeowner associations, and other organizations to manage speaker sign-up lists for public meetings.

Data Handling

CommTrail processes meeting attendee information (names, email addresses, and public comment topics) strictly on behalf of our customers and solely for the purpose of delivering the Meeting Signup service. We do not sell, share, or use attendee data for any commercial purpose. All data is stored in the United States. We act as a data processor; our customers retain ownership and control of their data at all times.

Technical Security Controls

The Meeting Signup platform implements the following security controls:

  • All data in transit encrypted via TLS 1.2 or higher; HTTPS enforced; HSTS enabled
  • All data at rest encrypted via AES-256 (Supabase/AWS managed encryption)
  • Role-based access control for staff accounts (admin and staff roles)
  • Database-level row security policies ensuring complete data isolation between organizations
  • Comprehensive audit logging of all data mutations with actor identity and timestamp
  • Rate limiting on all public-facing API endpoints to prevent abuse
  • Input validation on all data entry points using a structured schema validation library
  • Security headers including Content Security Policy, HSTS, X-Frame-Options, and Permissions-Policy

Infrastructure

The application is hosted on Microsoft Azure App Service, which provides 99.95% availability SLA, automated security patching, and physical security controls at Microsoft-operated data centers in the United States. Database services are provided by Supabase, Inc., operating on AWS infrastructure in US East. Both providers maintain their own compliance certifications including SOC 2 Type II.

Incident Response

In the event of a confirmed security incident involving customer data, CommTrail will notify affected organizations within seventy-two (72) hours of discovery. Our full breach notification commitment is documented in our Data Processing Agreement, available at signup.commtrail.com/legal/dpa.

Certifications

CommTrail does not currently hold SOC 2 Type II certification. We are committed to achieving SOC 2 Type II by 2027 as part of our enterprise readiness roadmap. This letter is provided as an interim attestation of our security practices for organizations that require a formal security statement prior to that certification.

I certify that the information provided in this letter is accurate and represents our current security practices as of the date above. For questions, additional documentation, or to submit a vendor security questionnaire for completion, please contact us at legal@commtrail.com.

Sincerely,

[Owner/Operator Signature]

Owner & Operator, CommTrail, LLC

legal@commtrail.com

Note: To obtain a signed PDF version of this letter for your procurement records, contact legal@commtrail.com.