Security and data

Your attendee list is yours. Here is how we look after it.

Most of what follows is the sort of thing you only find out by filling in a vendor questionnaire and waiting a fortnight. We would rather you could read it now and decide. Everything on this page is current as of September 2026 and we can evidence any of it on request.

Independent assessments

We would rather point at things somebody else checked than at our own assurances.

SOC 2 Type II data centre

Certified across all five Trust Services Criteria, independently audited over time rather than at a point in time.

PCI DSS Level 1

Card data is handled solely by Stripe and Square, each certified at the highest level the standard defines.

Canadian privacy law

Our hosting is compliant with PIPEDA, Canada’s federal private-sector privacy law, and with Ontario’s PHIPA.

What these certifications do and do not cover

We will say this plainly, because the distinction gets blurred a lot: the certifications above are held by the providers we build on, not by Eventist. Eventist does not hold a SOC 2 report or ISO 27001 certification. Our data centre is independently audited and our payment processors are PCI certified, and those controls genuinely protect your data — but they are their certifications, and anyone who presents an inherited certification as their own is selling you something. If your procurement process needs our control documentation, ask and we will provide it under NDA.

How we protect it

Where your data lives

Your event data is held in Canada, in a data centre that is SOC 2 Type II certified across all five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. That certification is an independent audit of controls operating over time, not a one-day snapshot. The facility operates entirely within Canada, so there are no cross-border transfers of your attendee data by default. Customers who need their data held in another country can have a dedicated deployment in a region of their choosing.

Encryption

All traffic to and from Eventist is encrypted in transit using TLS 1.2 or higher, and the connection between our application and its database is encrypted as well. Files you upload, along with tickets and media we generate, are encrypted at rest by our storage provider.

Card payments never touch us

Eventist does not store cardholder data. Payments are captured by Stripe or Square, each certified at PCI DSS Level 1, the highest level defined by the standard. Money settles into your own merchant account under your own agreement with the processor, so your ticket revenue is never held by us and never passes through our balance sheet.

Backups and recovery

Backups run automatically with point-in-time recovery, which means we can restore to any chosen moment rather than only to the previous night. Backups are retained for 30 days and copies are held separately from the primary system. Restores are tested, not assumed; the most recent test restore was carried out in August 2026.

Access control

Access to production systems is limited to the people who need it to do their jobs and is granted on a least-privilege basis. Inside your own account you control who sees what: roles are granular, and you can give a volunteer scanner access without giving them your sales figures. Administrative actions are logged.

Availability, published rather than promised

Our availability is monitored by an independent third party that tests both the website and the database every 60 seconds against tight response-time tolerances. Any irregularity is recorded as downtime and on-call engineers are notified immediately. The record is public and kept by the monitoring provider rather than by us, so you can read our history without asking us for it.

When something goes wrong

We have a documented incident response process covering detection, escalation and resolution. If an incident affects your data we will tell you, with what we know and what we are doing about it, rather than waiting until we have a complete picture. Incidents affecting the platform are posted to the public status page as they happen.

Who owns the data

The short version: you do, you can take it out at any time, and we do not make money from it in any way other than charging you to use the platform.

The data is yours

Attendee records, orders, registration answers, schedules and everything else generated by your event belong to you, not to us. We hold it to deliver the service you are paying for.

Export it whenever you like

Reports and data views export to CSV and Excel from inside the product, at any time, without asking us and without a fee. That includes orders, attendees, seats and registration question answers, and you can build a custom report if the built-in ones do not cover what you need. You do not have to be leaving to take your data with you.

It stays available after the event

Your data remains accessible in your account after your event ends, for as long as your account is open. Ending an event does not archive or lock your records.

We do not sell it, and we do not train on it

We do not sell attendee or organizer data. We do not share it with advertisers. We do not use it to train machine learning models, ours or anyone else’s. We do not market to your attendees. Your attendee list is yours, which is worth saying plainly because in this industry it often is not.

Deletion

You can delete your account and its data from within the product. Deletion is a real wipe rather than a flag, and we will confirm when it is done.

Filling in a vendor security questionnaire?

Send it to us. We answer them properly rather than returning a brochure, and we will tell you where we fall short of what you are asking for instead of leaving you to discover it at contract stage. Detail we do not publish here, including our data centre and hosting arrangements, sub-processor list and control documentation, is available to buyers under NDA.