How we protect your data and keep your events running safely.
Our commitment to security
EvenX is built for teams who run real events, where a data breach or system outage has direct operational consequences. Security is not an afterthought; it is part of how we build the product.
Infrastructure & hosting
Where your data lives, how it is transported, and how it is protected while at rest.
Hosting & region
EvenX is hosted entirely in the United Kingdom. Our application is deployed on Vercel (UK/EU region) and our database runs on Supabase, hosted on AWS eu-west-2 (London). Customer data does not leave the UK/EU without the controls described in the Subprocessors section below.
Data residency
Primary data storage is in the United Kingdom (AWS London, eu-west-2). EvenX serves customers globally. Certain subprocessors, including Stripe, Clerk, and OpenAI, may process data outside the UK as described in the Subprocessors section. All international transfers are governed by appropriate safeguards (UK IDTA or EU SCCs as applicable).
Encryption
In transit. All data transmitted between users and EvenX is encrypted using TLS 1.2 and TLS 1.3. Unencrypted HTTP connections are automatically redirected to HTTPS.
At rest. All customer data stored in our database is encrypted at rest using AES-256, enforced at the infrastructure level by AWS and Supabase.
Backups
Database backups are performed daily with a 30-day retention period. Backups are encrypted and stored separately from primary data.
Availability
EvenX targets 99.9% monthly uptime. Application infrastructure is managed by Vercel, which provides automatic failover, global CDN and DDoS protection. Database infrastructure is managed by Supabase on AWS, which provides multi-AZ redundancy.
Compliance & legal
How EvenX is registered, insured, and governed under UK data protection law.
Registrations
| Registration | Status |
|---|---|
| ICO Registration (UK GDPR) | Registered · ZC170755 |
| Company Registration | England & Wales · No. 16776145 |
| Cyber Liability Insurance | In place · underwritten by HISCOX |
GDPR & data protection
EvenX Ltd is the UK data controller for all customer data processed through the platform. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- We collect only the data necessary to provide the service
- We do not sell customer data to third parties
- We do not use customer event data to train AI models
- Data subjects may exercise their rights (access, erasure, portability) by contacting support@evenx.co.uk
- A Data Processing Agreement (DPA) is available upon request
Incident response
EvenX maintains an internal incident response procedure. In the event of a security incident that affects customer data:
- Affected customers are notified within 72 hours of EvenX becoming aware of the breach, in accordance with UK GDPR Article 33
- Notification includes the nature of the incident, categories of data affected, and steps taken to mitigate impact
- Serious incidents are reported to the ICO within the required timeframe
Data deletion
Upon account termination, customer data is deleted within 30 days. Encrypted backups are purged within the 30-day retention window. Written confirmation of deletion is available upon request.
Access & authentication
How your team signs in, what they can do once inside, and how those actions are recorded.
Authentication features
EvenX uses Clerk for authentication and identity management. Clerk is SOC 2 Type II certified. The following features are available to all EvenX customers:
- Email and password authentication with secure hashing
- Google OAuth single sign-on
- Role-based access control (RBAC) with Admin, Planner, Approver and Viewer roles
- Automatic session expiry after 45 minutes of inactivity
Enterprise SSO (SAML 2.0 / OIDC) is available on the Enterprise plan. Contact support@evenx.co.uk to discuss requirements.
Role-based access control
EvenX enforces role-based permissions across the platform. Organisation billing and settings are accessible to Admin roles only. Team members cannot access payment information, organisation configuration, or other users' personal data beyond what their role requires.
Audit logging
Authentication events, including sign-in, sign-out, and password changes, are logged via Clerk with a 90-day retention period.
People & operational security
Who can reach production, and how the application itself is tested.
Access to production systems
Access to production systems and customer data is restricted to authorised EvenX personnel on a least-privilege basis. Access is granted only where required for the role. All personnel with access to production data have agreed to confidentiality obligations.
Penetration testing
EvenX relies on the security controls and penetration testing programmes of its infrastructure partners. Vercel, Supabase, Clerk and Stripe each conduct regular third-party penetration tests. Independent third-party penetration testing of the EvenX application is planned prior to enterprise customer onboarding.
Subprocessors
Third parties that process customer data on our behalf. Each is bound by a data processing agreement.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database & file storage | UK (London) |
| Vercel | Application hosting & CDN | UK / EU |
| Stripe | Payment processing & billing | US (EU/UK DPA) |
| Clerk | Authentication & identity | US (SOC 2) |
| OpenAI | Eva AI features | US (DPA available) |
| Resend | Transactional email delivery | US |
An up-to-date subprocessor list is available upon request. EvenX will provide 30 days' notice of material changes to subprocessors that may affect data processing.
Security contact & responsible disclosure
If you find something, tell us. Here's how, and what you can expect back.
Reporting a vulnerability
If you discover a security vulnerability in our platform, please report it responsibly. Please include a clear description of the vulnerability, steps to reproduce it, and any evidence of potential impact. Do not attempt to access, modify or delete customer data as part of testing.
Our commitment
- We will acknowledge your report within 48 hours
- We will investigate and provide an update within 10 business days
- We aim to resolve confirmed vulnerabilities within 30 days of validation
- We will not pursue legal action against researchers who report in good faith
EvenX does not currently operate a bug bounty programme. We recognise and thank all researchers who responsibly disclose vulnerabilities.