Security and trust
Written for the reviewer: what an ISO 27001 certified event platform holds, tests and does with your data, stated plainly. Everything on this page is the standing position - nothing needs a call to explain.
Certifications
ISO 27001
Certified information security management, independently audited. Not a higher-tier add-on.
Cyber Essentials
Accredited under the UK government scheme.
Testing
Client-commissioned penetration testing
Tier-1 banks run their own penetration tests through security firms they choose, on the scope they choose.
Our own annual test
We commission an OWASP-standard penetration test annually.
Due diligence
Continuous TPRM
Clients put every claim we make through continuous third-party risk management. Every claim evidenced, not asserted.
Client-run audits
Recurring. Corporate banks audit us directly, not only the bodies that certify us.
Data handling
GDPR
Data handled to European standards by default, with residency options.
Data processing
Eventogy operates as a GDPR-compliant data processor under Article 28. A Data Processing Agreement is available for all enterprise clients.
Access control
Roles, permissions and delegated access. Everyone sees only their part.
Authentication
SAML-based SSO, integrating with your existing identity provider.
Hosting
Hosted on AWS infrastructure.
Platform
Dedicated instance
Your programme runs on its own dedicated instance. Your data sits with no other customer's.
Encryption
Data encrypted at rest and in transit.
Availability
99.97% uptime, measured across every event we run.
Seen in the product
Questions we are asked in review
Which certifications does Eventogy hold?
ISO 27001 for information security management, independently audited, and Cyber Essentials under the UK government scheme. Neither is a higher-tier add-on.
Where is Eventogy data hosted?
On AWS infrastructure. Data is handled to European standards by default, with residency options, and is encrypted at rest and in transit.
Who runs penetration testing against the platform?
Both sides. Tier-1 banks run their own penetration tests through security firms they choose, on the scope they choose, and we commission an OWASP-standard penetration test annually.
Is a Data Processing Agreement available?
Yes. Eventogy operates as a GDPR-compliant data processor under Article 28, and a Data Processing Agreement is available for all enterprise clients.
For your review
Anything your review needs that is not on this page - the DPA, evidence packs, or a session with the team - comes through info@eventogy.com.