UK-hosted, GDPR-aligned
Event data is hosted in the UK on AWS London. The platform is GDPR-aligned and DPA-ready, and customer data is not used to train third-party AI models — which matters increasingly often in a security review, because most event platforms cannot say it.
- UK data hosting (AWS London)
- GDPR-aligned and DPA-ready
- AES-256 encryption
- Customer data not used to train third-party models
Access control that survives an audit
Single sign-on via OIDC and SAML puts account access behind your own identity provider, so joiners and leavers are handled where they should be. Beneath that, role-based access with MFA scopes what each person can reach, and per-event team groups narrow it further to the events they actually work on.
- SSO via OIDC and SAML
- Role-based access with enforced MFA
- Per-event team groups
A tamper-evident audit trail
Administrative actions are recorded in an audit trail designed so entries cannot be quietly altered after the fact. When someone asks who changed a registration setting three weeks ago, or who exported an attendee list, the answer is in the platform rather than in somebody's memory.
Where we are on certification
SOC 2 Type 1 is in progress, targeted for Q4 2026. We would rather state that plainly than imply a certification we do not yet hold — if your procurement process requires a completed SOC 2 report today, that is worth raising with us early rather than late.
Scale across the organisation
One account runs an unlimited programme of events across multiple teams, each white-labelled on its own domain if needed, with one place to see how the whole programme is performing.