Event Software Security Scorecard
Vet Any Event Platform Before You Trust It With Your Data
The questions to ask before an event platform holds your attendee data. Eight areas, one pass, under 30 minutes.
0% complete0 of 8 areas scored
Security areaThe question to askStrong answerRed flagYour score
Certifications
“What does each certification cover, and can we see the report?”
Green flagNamed certs (e.g. SOC 2 Type II, ISO 27001) with scope stated, reports shared under NDA with current dates
Red flag“We’re ISO 27001 certified” with no scope, or a trust page instead of a document
Data location
“Which regions is our data stored in, and is residency in the contract?”
Green flagNamed hosting provider and regions, residency committable as a contract term
Red flag“The cloud” or continents only; residency offered as a hidden setting, not a term
Encryption
“Is data encrypted in transit and at rest, including backups?”
Green flagCurrent standards both ends, backups covered, clear key management
Red flagVague “bank-grade” or “enterprise-grade” with no specifics
Identity & access
“Is single sign-on on our plan, and can we set roles ourselves?”
Green flagSSO without a paid upgrade, admin-configurable roles, MFA available
Red flagSSO “on request” (usually a bigger contract), or the vendor has to change roles for you
Exports & audit
“Who can export the attendee list, and is each export logged?”
Green flagExports limited by role and logged with user and timestamp
Red flagAnyone can export, and exports are not recorded
Privacy
“Is a data processing agreement standard, and will you share a subprocessor list?”
Green flagStandard DPA, full subprocessor list, notice before changes, GDPR/CCPA covered
Red flagDPA only after negotiation, no subprocessor list on hand
Retention & exit
“What happens to our data when the contract ends?”
Green flagStated retention window, full export, written confirmation of deletion
Red flag“We’d delete it,” with no window and no confirmation
Incident response
“Is your breach-notification window in the contract, in hours?”
Green flagA number of hours in the contract, plus an incident response plan tested in the last year
Red flag“As soon as reasonably practicable,” and nothing more