Security & compliance.
How Eventtia secures the platform and the data it holds — built on the SOC 2 framework, audited by independent third parties, hosted on AWS, encrypted end-to-end.
The full program. Cleanly mapped.
A quick map of the security program before you dive in. Each section collects related controls — jump to the area you need.
SOC 2 program, third-party audits, penetration testing, training, confidentiality, and background checks.
AWS hosting, encryption at rest and in transit, vulnerability scanning, monitoring, DR, and incident response.
SSO, 2FA, least-privilege access, quarterly access reviews, password policy, and password managers.
Annual risk assessments and vendor risk management before authorizing any new vendor.
How to reach the team if you have a question, concern, or want to report a security issue.
Security & compliance, in full.
Application performance monitoring, security & compliance — the controls Eventtia operates across the program, the cloud, and the team that runs it.
1. Organizational Security
A comprehensive program integrated throughout the organization, based on the SOC 2 Framework established by the AICPA.
We willingly submit to impartial, third-party evaluations that assess our security measures and compliance controls rigorously.
At a minimum, we conduct independent third-party penetration tests annually to guarantee the security integrity of our services.
Roles and responsibilities for the Information Security Program and safeguarding client data are documented. All team members must review and comply with every established policy.
All team members are required to complete employee security awareness training covering industry-standard techniques such as phishing and password management.
Each team member must sign and uphold an industry-standard confidentiality agreement before commencing their initial day of work.
We conduct comprehensive background checks on all prospective team members in strict compliance with local legislation.
2. Cloud Security
Services are hosted on Amazon Web Services (AWS), which operates a robust security program with numerous certifications. See AWS Security.
All data is stored on AWS databases. Each of these databases is situated within the United States.
All databases are securely encrypted while at rest.
Our applications encrypt in transit with TLS/SSL only.
We perform vulnerability scanning and actively monitor for threats.
We actively monitor and log various cloud services.
We use our data hosting provider's backup services to reduce data-loss risk in the event of hardware failure, and use monitoring services to alert the team if failures affect users.
We have a process for handling information security events, including escalation procedures, rapid mitigation, and communication.
3. Access Security
Access to cloud infrastructure and other sensitive tools is limited to authorized employees who require it for their roles. Where available, we have Single Sign-on (SSO), 2-factor authentication (2FA), and strong password policies to protect access to cloud services.
We follow the principle of least privilege for identity and access management.
We perform quarterly access reviews of all team members with access to sensitive systems.
All team members must adhere to a minimum set of password requirements and complexity for access.
All company-issued laptops utilize a password manager for team members to manage passwords and maintain password complexity.
4. Vendors & Risk Management
We undergo at least annual risk assessments to identify potential threats, including considerations for fraud.
Vendor risk is determined, and the appropriate vendor reviews are performed before authorizing a new vendor.
5. Contact Us
If you have any questions, comments, or concerns, or if you wish to report a potential security issue, please contact [email protected].
See something concerning? Tell us.
Security disclosures, audit requests, and compliance questions go to the same address. We acknowledge reports promptly and follow up with a remediation plan when one applies.