← All policies

Security Policy

Effective Date: July 24, 2026 Last Updated: July 24, 2026

This Security Policy describes the technical and organizational measures we use to protect your Personal Data. It supplements our Privacy Policy.

1. Authentication

1.1 Accounts are protected by either a password (see §3) or a third-party sign-in (Google, Apple, or Facebook). Third-party sign-ins are cryptographically verified against the provider itself — we do not trust identity claims asserted by the client device.

1.2 Sessions use signed, time-limited session tokens. A token is automatically invalidated if the account's password is changed, so a still-valid token cannot outlive a deliberate password reset (e.g., after a suspected compromise).

1.3 A banned or deleted account is rejected on its very next request, even if it is still holding a previously valid session token.

2. Encryption

2.1 All data in transit between the App and our servers is encrypted using HTTPS/TLS.

2.2 Passwords are never stored in plain text — they are hashed using the industry-standard bcrypt algorithm before storage.

2.3 One-time passcodes (OTPs) used for password reset and email verification are stored as one-way cryptographic hashes, not in plain text, and expire automatically after a short, fixed window.

3. Password Security

3.1 Passwords must be a minimum of 8 characters.

3.2 We never send you your password by email or display it anywhere after creation — if you forget it, you must reset it via the OTP-based "Forgot Password" flow.

4. Payment Security

4.1 We do not process or store your full card, bank, or UPI credentials on our servers. Payments are handled directly by our payment gateway's own secure, PCI-DSS-compliant infrastructure. See our Payment Policy for details.

5. Access Controls

5.1 The App enforces role-based access control (Participant, Organizer, Administrator) — each role can only access the data and actions appropriate to it.

5.2 Organizer KYC documents (identity proof, address proof, PAN/Aadhaar) are stored in a private storage location that is never publicly accessible. They can only be viewed via short-lived, time-limited access links generated on demand for authorized administrative review.

5.3 Administrative actions (approvals, rejections, bans, refund decisions) are logged in an internal audit trail recording who took the action, what it was, and when.

6. Abuse Prevention

6.1 Authentication and other sensitive endpoints are rate-limited to reduce the risk of automated credential-stuffing or brute-force attacks.

7. Incident Response

7.1 If we become aware of a security incident that affects your Personal Data, we will take reasonable steps to investigate, contain, and remediate it, and will notify affected users and, where legally required, the relevant regulatory authority, without undue delay.

7.2 If you believe you have discovered a security vulnerability in the App, please report it responsibly to the contact below rather than disclosing it publicly, so we can investigate and address it.

8. Contact

Support Email: support@eventrix.app

For a security vulnerability report or a security-related incident, please mark your message accordingly so it can be prioritized appropriately.