Skip to content

Security & compliance

Built with the same standards as enterprise SaaS — appropriate for organizations of every size.

  • HTTPS everywhere with modern TLS and strict transport security.
  • PCI-DSS compliant payments via Stripecard data never enters our database.
  • Encrypted at rest on PostgreSQL, with daily encrypted backups available.
  • Bcrypt password hashing (cost 12)we can't see your password.
  • Two-factor authentication (TOTP)Organizers and staff can turn on app-based MFA (Google Authenticator, Authy, 1Password) with encrypted secrets and single-use recovery codes.
  • Cryptographically signed QR codestickets cannot be forged or duplicated.
  • Single-use invite tokens that expire after 7 days. Stale links can't be used.
  • Rate limiting on authentication and check-in endpointsbrute-force protection built in.
  • Audit logging on every organizer and staff actionaccountability without spreadsheets.
  • Role-based access control with hard isolation between organizations.
  • GDPR-friendly data handling with export and delete endpoints for attendees who request it.

Have a security question or need to report something? Email events@yourevents.app.