Trust & Security

Evently is where exhibiting teams keep their meetings, their attendees and their pipeline. This page sets out how we protect that information, and where to find the agreements that govern it.

Last updated September 7, 2026

Our approach

How we think about security

Protect

We implement technical and organizational safeguards designed to protect customer and personal information.

Control

Access to systems and information is restricted based on business need and appropriate authorization.

Monitor

We review our environment and security controls to identify and respond to potential threats.

Improve

Our security program is regularly reviewed and improved as technology, threats, and customer requirements evolve.

Compliance

Independent assurance

SOC 2 Type II

Current report on file

Evently's controls are independently evaluated against the applicable SOC 2 Trust Services Criteria.

ISO/IEC 27001

Certified

Evently maintains an information security management system aligned with the ISO/IEC 27001 standard.

Documentation

Agreements and security documents

DocumentAccess
Master Software as a Service AgreementThe terms governing the Evently platform and services.View
Data Processing AddendumData processing terms for customers.View
Service Level AgreementAvailability commitments and service credits.View
AI & Autonomous Agent Security/Controls ScheduleControls governing AI features and any autonomous agent behaviour.View
Enterprise SaaS Order FormThe order form used for enterprise subscriptions.View
Security OverviewSummary of Evently's security program.View
Business Continuity & DR OverviewOverview of continuity and recovery practices.Request

Privacy

Policies and legal terms

Privacy Policy

How Evently collects, uses, stores, and protects personal information.

Terms & Conditions

The terms governing use of the Evently platform and services.

Data Processing Addendum

Terms governing the processing of personal data on behalf of customers.

Cookie Policy

Information about cookies and similar technologies used by Evently.

Data protection

How customer information is handled

Data Minimization

We seek to collect and process information necessary to provide and improve our services.

Access Controls

Access to customer information is restricted according to role and business need.

Encryption

Data is protected using appropriate encryption and security controls during transmission and storage.

Retention & Deletion

We maintain policies governing retention and deletion of information.

Third-Party Risk Management

Third-party service providers are evaluated as part of our security and vendor management program.

Privacy & Compliance

We maintain policies and processes designed to support applicable privacy and data protection requirements.

Security overview

Our security practices

Infrastructure Security

Evently is hosted on cloud infrastructure with logical tenant separation and network security controls. Production Services target a 99.9% Monthly Uptime Percentage, backed by documented backup and disaster-recovery procedures with a 24-hour Recovery Point Objective and an 8-hour Recovery Time Objective, as set out in the Service Level Agreement.

Application Security

Our software-development lifecycle includes secure coding practices, mandatory code review, and dependency management.

Vulnerability Management

We run periodic vulnerability assessments of production infrastructure and arrange penetration testing by qualified independent professionals at least annually, as committed in the Master SaaS Agreement, with a risk-based program for remediating identified issues.

Identity & Access Management

Access follows least-privilege and role-based access control principles. Signing in with a password from an unrecognised device requires a second factor — a time-based one-time code where enrolled, otherwise a single-use code sent by email. Evently supports enterprise identity via SAML 2.0, OpenID Connect, SSO, and SCIM provisioning where included in the applicable subscription.

Encryption

Customer Data is encrypted in transit and at rest using industry-standard protocols, both within Evently's own environment and by contractually required third-party AI and infrastructure providers.

Security Monitoring & Incident Response

Production systems are covered by infrastructure, application and security logging, with alerting and incident escalation. Following a confirmed security incident involving Personal Data, we notify affected customers without undue delay — and within 48 hours where practicable, as set out in the Data Processing Addendum.

Employee Security

Personnel authorized to process Personal Data are subject to confidentiality obligations, security-awareness training, and access controls appropriate to their role.

Business Continuity

We maintain documented backup, business-continuity, and disaster-recovery procedures, with periodic backups protected by security controls consistent with those protecting production Customer Data.

Security questions

Need additional information?

We understand that security reviews are an important part of evaluating a SaaS provider. If you're conducting a security, privacy, compliance, or procurement review of Evently and need information that isn't available above, our team can help — for formal reviews, we can provide additional documentation where appropriate and subject to confidentiality requirements.

Request documentation

Request Security Documentation

What information are you requesting? *
Reason for Request *

Submitting opens an email to Privacy@evently.ai with these details filled in — nothing is sent from this page directly.

Confidence starts with transparency.

We're committed to earning your trust — before, during, and after you choose Evently.