Evently is where exhibiting teams keep their meetings, their attendees and their pipeline. This page sets out how we protect that information, and where to find the agreements that govern it.
Last updated September 7, 2026
Our approach
We implement technical and organizational safeguards designed to protect customer and personal information.
Access to systems and information is restricted based on business need and appropriate authorization.
We review our environment and security controls to identify and respond to potential threats.
Our security program is regularly reviewed and improved as technology, threats, and customer requirements evolve.
Compliance
Current report on file
Evently's controls are independently evaluated against the applicable SOC 2 Trust Services Criteria.
Certified
Evently maintains an information security management system aligned with the ISO/IEC 27001 standard.
Documentation
| Document | Access |
|---|---|
| Master Software as a Service AgreementThe terms governing the Evently platform and services. | View |
| Data Processing AddendumData processing terms for customers. | View |
| Service Level AgreementAvailability commitments and service credits. | View |
| AI & Autonomous Agent Security/Controls ScheduleControls governing AI features and any autonomous agent behaviour. | View |
| Enterprise SaaS Order FormThe order form used for enterprise subscriptions. | View |
| Security OverviewSummary of Evently's security program. | View |
| Business Continuity & DR OverviewOverview of continuity and recovery practices. | Request |
Privacy
How Evently collects, uses, stores, and protects personal information.
The terms governing use of the Evently platform and services.
Terms governing the processing of personal data on behalf of customers.
Information about cookies and similar technologies used by Evently.
Data protection
We seek to collect and process information necessary to provide and improve our services.
Access to customer information is restricted according to role and business need.
Data is protected using appropriate encryption and security controls during transmission and storage.
We maintain policies governing retention and deletion of information.
Third-party service providers are evaluated as part of our security and vendor management program.
We maintain policies and processes designed to support applicable privacy and data protection requirements.
Security overview
Evently is hosted on cloud infrastructure with logical tenant separation and network security controls. Production Services target a 99.9% Monthly Uptime Percentage, backed by documented backup and disaster-recovery procedures with a 24-hour Recovery Point Objective and an 8-hour Recovery Time Objective, as set out in the Service Level Agreement.
Our software-development lifecycle includes secure coding practices, mandatory code review, and dependency management.
We run periodic vulnerability assessments of production infrastructure and arrange penetration testing by qualified independent professionals at least annually, as committed in the Master SaaS Agreement, with a risk-based program for remediating identified issues.
Access follows least-privilege and role-based access control principles. Signing in with a password from an unrecognised device requires a second factor — a time-based one-time code where enrolled, otherwise a single-use code sent by email. Evently supports enterprise identity via SAML 2.0, OpenID Connect, SSO, and SCIM provisioning where included in the applicable subscription.
Customer Data is encrypted in transit and at rest using industry-standard protocols, both within Evently's own environment and by contractually required third-party AI and infrastructure providers.
Production systems are covered by infrastructure, application and security logging, with alerting and incident escalation. Following a confirmed security incident involving Personal Data, we notify affected customers without undue delay — and within 48 hours where practicable, as set out in the Data Processing Addendum.
Personnel authorized to process Personal Data are subject to confidentiality obligations, security-awareness training, and access controls appropriate to their role.
We maintain documented backup, business-continuity, and disaster-recovery procedures, with periodic backups protected by security controls consistent with those protecting production Customer Data.
Security questions
We understand that security reviews are an important part of evaluating a SaaS provider. If you're conducting a security, privacy, compliance, or procurement review of Evently and need information that isn't available above, our team can help — for formal reviews, we can provide additional documentation where appropriate and subject to confidentiality requirements.
Request documentation
We're committed to earning your trust — before, during, and after you choose Evently.