Your data, protected

EventfullyManaged is built on the Burdenoff platform with security and privacy designed in from the start.

Encryption in transit & at rest
Role-based access control
Privacy-first defaults

How we protect your events

The measures that protect your data and your attendees' trust.

Encryption in Transit & at Rest

Traffic between your browser and our servers is protected with TLS, and data is encrypted at rest.

TLS for all communications
Encrypted data storage
Secure API endpoints
Modern cipher suites

Role-Based Access Control

Every action is scoped by role and protected by the Burdenoff platform’s RBAC — organizers, staff, and volunteers see only what they should.

Granular per-role permissions
Field-level authorization
Attributable, audited changes
Least-privilege by default

Secure, Isolated Data

Event and attendee data is stored on managed cloud infrastructure with tenant isolation and regular backups.

Multi-tenant isolation
Automated backups
Managed cloud infrastructure
Access logging

Account Protection

Authentication is handled centrally by the platform, with protections designed to keep accounts safe.

Centralised authentication
Session protection
Suspicious-activity monitoring
Designed for MFA support

Privacy Protection

Your privacy matters to us. Here's how we protect your personal information.

Data Minimization

We collect only the data needed to run your events and improve the product — nothing more.

Transparent Policies

Our privacy policy clearly explains what we collect, how we use it, and your rights.

User Control

You can view, edit, export, or delete your information through your account and on request.

No Data Selling

We never sell your personal data, and we never use it for undisclosed purposes.

Our Security Principles

The principles that guide how we build and operate the platform.

Secure by Design

Security is built into the platform from the start, not bolted on later.

Privacy by Default

Conservative defaults that protect attendee data out of the box.

Least Privilege

People and services get only the access they genuinely need.

Defense in Depth

Layered protections across the network, application, and data tiers.

Compliance & Certifications

We believe in being upfront about where we are today versus where we're headed.

SOC 2 Type II

Roadmap

Independent SOC 2 Type II attestation is on our roadmap and not yet in force. We will publish the report here once complete.

ISO/IEC 27001

Roadmap

An ISO/IEC 27001-aligned ISMS is being built out; formal certification is planned and not yet achieved.

GDPR / DPDP Act

DPA available

A Data Processing Addendum covering GDPR and the Indian DPDP Act is available for Enterprise agreements.

Security Exhibit

Available on request

A Security Exhibit detailing our technical and organisational measures is available to Enterprise customers as part of the contract stack.

EventfullyManaged is pre-launch. SOC 2 Type II and ISO/IEC 27001 are target-state commitments we are building toward, not certifications currently held — we will update this page the moment either is independently attested. Enterprise customers can request our Security Exhibit and DPA today.

Stay safe with EventfullyManaged

A few best practices to keep your account and your events secure.

Use Strong Passwords

Create a unique, complex password and enable multi-factor authentication when it’s available.

Manage Team Access

Give staff and volunteers only the roles they need, and remove access when an event ends.

Verify Communications

We’ll never ask for your password. Check that emails and links come from official sources.

Report Suspicious Activity

If something looks off with your account or event, contact us right away so we can help.

Responsible Disclosure

Found a potential security issue? We welcome responsible disclosure from researchers and users. Email our team with the details and we'll investigate promptly.

Secure by Design

Run your events with confidence on a platform built for security and privacy.