Security & compliance
Built with the same standards as enterprise SaaS — appropriate for organizations of every size.
- HTTPS everywhere with modern TLS and strict transport security.
- PCI-DSS compliant payments via Stripe — card data never enters our database.
- Encrypted at rest on PostgreSQL, with daily encrypted backups available.
- Bcrypt password hashing (cost 12) — we can't see your password.
- Two-factor authentication (TOTP) — Organizers and staff can turn on app-based MFA (Google Authenticator, Authy, 1Password) with encrypted secrets and single-use recovery codes.
- Cryptographically signed QR codes — tickets cannot be forged or duplicated.
- Single-use invite tokens that expire after 7 days. Stale links can't be used.
- Rate limiting on authentication and check-in endpoints — brute-force protection built in.
- Audit logging on every organizer and staff action — accountability without spreadsheets.
- Role-based access control with hard isolation between organizations.
- GDPR-friendly data handling with export and delete endpoints for attendees who request it.
Have a security question or need to report something? Email events@yourevents.app.
