Security and trust
Written for the reviewer: certifications, testing and data handling, stated plainly. Everything on this page is the standing position - nothing needs a call to explain.
Certifications
ISO 27001
Certified information security management, independently audited. Not a higher-tier add-on.
Cyber Essentials
Accredited under the UK government scheme.
Testing
Client-commissioned penetration testing
Tier-1 banks run their own penetration tests through security firms they choose, on the scope they choose.
Our own annual test
We commission an OWASP-standard penetration test annually.
Due diligence
Continuous TPRM
Clients put every claim we make through continuous third-party risk management. Every claim evidenced, not asserted.
Client-run audits
Recurring. Corporate banks audit us directly, not only the bodies that certify us.
Data handling
GDPR
Data handled to European standards by default, with residency options.
Data processing
Eventogy operates as a GDPR-compliant data processor under Article 28. A Data Processing Agreement is available for all enterprise clients.
Access control
Roles, permissions and delegated access. Everyone sees only their part.
Authentication
SAML-based SSO, integrating with your existing identity provider.
Hosting
Hosted on AWS infrastructure.
Platform
Dedicated instance
Your programme runs on its own dedicated instance. Your data sits with no other customer's.
Encryption
Data encrypted at rest and in transit.
Availability
99.97% uptime, measured across every event we run.
Seen in the product
For your review
Anything your review needs that is not on this page - the DPA, evidence packs, or a session with the team - comes through info@eventogy.com.