Plan corporate events, from invitation to reporting.
HEIvent brings event website, registration, travel, hotels, check-in and analytics together in one platform. Free, hosted in Germany.

For corporate events with guests on site
Customer days, conferences, internal events. Wherever guests travel and stay overnight, are checked at the entrance, and attendance has to be documented afterwards.
Eleven areas, one system
Registration, travel, hotels, check-in and analytics work on the same data. What a guest enters at registration is in the arrival list, the rooming list and at the entrance, with no reconciling and no spreadsheet in between.
Arrival and shuttle
Your guests’ flights and trains are assigned to an arrival point, and from there your team plans the shuttles. Bus operators and drivers work through their own access.
Event website
Builder with blocks and several pages per event. Earlier versions can be restored, every page has its own SEO settings.
Registration and tickets
Ticket types with quotas, waiting list with automatic promotion, separate registration tracks per audience, your own form fields, and on request approval of every registration by the organiser.
Programme and sessions
Guests book sessions themselves. Every seat is firmly allocated at booking time, time clashes are detected, waiting lists per session.
Check-in and admission
QR code in the confirmation email. When it is reissued, the old one becomes invalid. Self-service terminal at the reception desk, live count per entrance.
Badges
Badge designer with live preview, five formats, batch PDF for bulk printing, direct printing to Zebra label printers on the network.
Hotels and rooms
Allotments per hotel, radius search around the venue, rooming list as an export. The last free room is given out only once, even if two people book at the same time.
Communication
Emails in your own design, if-then automations before and after the event, multi-step sequences, open and click rates.
Analytics
Registration, check-in, session attendance and lead scans are recorded per guest. From that come funnels and reports you can pass on by link.
Staff, equipment, schedule
Team with roles and tasks, equipment inventory with availability check, minute-by-minute run of show for the event day.
Budget and privacy
Budget items with multi-level approval via link and escalation when the deadline passes. Retention periods, data access and deletion under GDPR.
14 of 22 milestones reached5 in progress3 plannedTo the development status
How HEIvent works
Four stations on real screen recordings. Registration as the guest sees it, then guest list, travel and cockpit from the dashboard.

The guest registers
The event website is built in the dashboard and is public immediately. What the guest enters there is in your guest list with no intermediate step.
From the rooming list to the report
- 3 days before
Rooming list to the hotel
Rooms, arrival times and host per guest as an export, from the same data as the arrival list.
Hotels and rooms - 2 days before
Waiting list moves up
Two cancellations, two guests promoted from the waiting list, both informed automatically by email, without anyone touching the list.
Programme and sessions - Day before, 16:12
Arrival as per travel data
LH 436 lands in Frankfurt, shuttle 1 leaves at 17:00. The driver reports boarding through their access, the host sees it in the dashboard.
Arrival and shuttle - Event day, 06:30
Set-up by run of show
The team sees on their phones who has to be where and when. The projector for room 2 is marked as booked.
Staff, equipment, schedule - 07:30
Reception opens
Guests check themselves in at the terminal, the badge comes out of the label printer. Anyone who cannot find their code is checked in via search.
Check-in and admission - 09:05
Attendance per session
Guests scan the code at the room. The control room shows live how full each room is.
Programme and sessions - 10:40
Exhibitor scans leads
Stand staff with their own scanner link, no account. Every scan lands in the guest’s contact history.
Analytics - Day after
The report is in
Funnel, check-in timeline, attendance per session. Report link for management and clients without an account, CSV export for your own analysis.
Analytics
Seven kinds of access by link. Without an account.
Speakers, sponsors, exhibitors, bus operators, drivers, approvers and stand staff get a personal link. Nobody creates an account, nobody maintains one. What a speaker enters there, their travel notes for instance, then sits with their data in the dashboard.
Enter photo, biography, materials, technical needs and travel notes yourself.
Maintain the profile, view the booked package, agreed services and reach.
Stand profile, materials and equipment for the stand, plus the lead scanner.
Accept the request, report vehicle and driver.
Passenger list, boarding by QR scan and status updates on the road.
Budget approval via link, with escalation when the deadline passes.
Their own scanner link for leads, without access to the stand profile.
Pricing
Community edition and Managed instance are the same software. The difference is in operations, that is whether you share the infrastructure with others and whether availability and support are committed.
The complete platform on shared infrastructure. Create an account, start an event.
- Full feature set: no locked areas
- Unlimited events, guests and team members
- Event websites under the platform’s address
- All GDPR tools, servers in Germany
- Start without payment details, trial period or sales call
- Help through the built-in guide and the contact form
The same platform, operated for you alone, with a separate database, your own domain and support by email.
- Everything from the Community edition
- Your own isolated instance: separate database and file storage
- Your own domain, TLS certificate included
- Daily backups with verified restore
- We take care of updates and monitoring
- Support by email, answered by the operators
Details and the full comparison are on the pricing page.
Privacy and security, verifiable
Instead of badges we show measurements. The figures below come from the automated check of 13 September 2026 and are regenerated every day.
What we do not have
No ISO 27001 or SOC 2 certification, no external penetration test, no third-party audit. If you strictly need that, we are not the right choice today. We would rather say so now than in your IT department’s security questionnaire.
All 12 measures in detail
Operated in Germany
Servers, database, object storage and identity management run on EU infrastructure (Hetzner, Nuremberg and Falkenstein). There is no copy outside the EU. The optional AI features call a US service and can be switched off.
Personal data fields stored encrypted
74 of 108 populated columns with personal data are stored AES-256-GCM encrypted (68,5 %): names, addresses, companies, check-in identifiers. Not just the backup, the field itself.
Searching despite encryption
Registration, admission and duplicate checks run on a blind index (an HMAC per column), not on plaintext. The database can compare values without knowing them.
Encrypted before the value reaches the database
100 columns are encrypted at write time, not in a later pass. A guard inside the database sees every plaintext value that bypasses the application, 0 in the last 24 hours. Once it stays quiet, it rejects instead of counting.
Tenant isolation, tested daily
Row-level security in the database, deliberately fail-closed: without tenant context the database returns nothing rather than everything. 180 read endpoints are actively tested against the tenant boundary every day, most recently without findings.
Endpoints, each with a defined access rule
For all 1,053 endpoints it is decided who may call them; a build check breaks as soon as a new endpoint appears without a decision. Two-factor authentication is mandatory for administrative roles and cannot be disabled.
Time until a blocked account loses access
A blocked account loses access within five seconds, even with a token that would technically still be valid.
Log entries, checked for gaps and tampering
Security-relevant events are append-only and chained with checksums; most recently 19,761 entries verified, chain intact. Removing rows breaks the chain visibly.
Weekly restore test of the backups
Daily, encrypted, restored as a test every week, most recently passed, 42,658 rows. 174 encrypted values from the copy are actually decrypted in the process: a backup that restores but contains only ciphertext would be worthless.
Access, erasure and objection implemented
Access, rectification, erasure, restriction, portability and objection are implemented. A completed erasure request triggers anonymisation instead of merely setting a status. Retention periods are enforced by a daily job.
Reporting channel for vulnerabilities
Published at /.well-known/security.txt following RFC 9116, with a contact address and expiry date. No bug bounty: a reply may take one working day.
Automated checks, daily
27 checks run on every change and every night; their results go into a dated evidence package with a checksum. It contains no personal data and is available on request for vendor assessments.
Frequently asked questions
What does HEIvent cost?
What is the catch with the free edition?
Can I download HEIvent and run it myself?
Where is the data hosted?
Which features does HEIvent cover?
Can we use our own domain?
What happens to guest data after the event?
How is guest data protected in HEIvent?
Are there apps for the event day?
Does HEIvent support single sign-on?
Your next event starts here.
Create an account, publish the event website, open registration. It takes an afternoon and costs nothing.


