Legal

Security & compliance.

How Eventtia secures the platform and the data it holds — built on the SOC 2 framework, audited by independent third parties, hosted on AWS, encrypted end-to-end.

The full text

Security & compliance, in full.

Application performance monitoring, security & compliance — the controls Eventtia operates across the program, the cloud, and the team that runs it.

1. Organizational Security

Information Security Program

A comprehensive program integrated throughout the organization, based on the SOC 2 Framework established by the AICPA.

Third-party audits

We willingly submit to impartial, third-party evaluations that assess our security measures and compliance controls rigorously.

Third-party penetration testing

At a minimum, we conduct independent third-party penetration tests annually to guarantee the security integrity of our services.

Role definition & responsibilities

Roles and responsibilities for the Information Security Program and safeguarding client data are documented. All team members must review and comply with every established policy.

Security awareness training

All team members are required to complete employee security awareness training covering industry-standard techniques such as phishing and password management.

Confidentiality

Each team member must sign and uphold an industry-standard confidentiality agreement before commencing their initial day of work.

Background checks

We conduct comprehensive background checks on all prospective team members in strict compliance with local legislation.

2. Cloud Security

Cloud infrastructure security

Services are hosted on Amazon Web Services (AWS), which operates a robust security program with numerous certifications. See AWS Security.

Data hosting

All data is stored on AWS databases. Each of these databases is situated within the United States.

Encryption at rest

All databases are securely encrypted while at rest.

Encryption in transit

Our applications encrypt in transit with TLS/SSL only.

Vulnerability scanning

We perform vulnerability scanning and actively monitor for threats.

Logging & monitoring

We actively monitor and log various cloud services.

Business continuity & DR

We use our data hosting provider's backup services to reduce data-loss risk in the event of hardware failure, and use monitoring services to alert the team if failures affect users.

Incident response

We have a process for handling information security events, including escalation procedures, rapid mitigation, and communication.

3. Access Security

Permissions & authentication

Access to cloud infrastructure and other sensitive tools is limited to authorized employees who require it for their roles. Where available, we have Single Sign-on (SSO), 2-factor authentication (2FA), and strong password policies to protect access to cloud services.

Least-privilege access control

We follow the principle of least privilege for identity and access management.

Quarterly access reviews

We perform quarterly access reviews of all team members with access to sensitive systems.

Password requirements

All team members must adhere to a minimum set of password requirements and complexity for access.

Password managers

All company-issued laptops utilize a password manager for team members to manage passwords and maintain password complexity.

4. Vendors & Risk Management

Annual risk assessments

We undergo at least annual risk assessments to identify potential threats, including considerations for fraud.

Vendor risk management

Vendor risk is determined, and the appropriate vendor reviews are performed before authorizing a new vendor.

5. Contact Us

If you have any questions, comments, or concerns, or if you wish to report a potential security issue, please contact help@eventtia.com.

Reporting a security issue

See something concerning? Tell us.

Security disclosures, audit requests, and compliance questions go to the same address. We acknowledge reports promptly and follow up with a remediation plan when one applies.

Email the security team →