Discover our encryption standards, access controls, and security practices safeguarding your event data.
All data in transit is encrypted using 256-bit TLS/SSL protocols. HTTP Strict Transport Security (HSTS) is enforced to ensure no unencrypted connections take place.
We strictly operate a zero credit card storage architecture. Paid subscriptions are processed via PCI-DSS compliant hosted payment gateways. Raw card numbers never touch our servers.
Guest QR passes rely on 32-character high-entropy cryptographic hashes. Invalid or modified tokens are immediately rejected with HTTP 404 status codes by gate scanners.
All administrative forms utilize anti-CSRF token verification and sanitized output encoding to protect users against XSS, SQL Injection, and session hijacking.