Security at Eventia
Your money and your data deserve real protection. Here's exactly how we keep them safe.
TLS everywhere
All data in transit is encrypted with TLS 1.3. We enforce HSTS and DNSSEC on all domains.
PCI-DSS compliant payments
Card data never touches our servers. All card processing is handled by PCI-DSS Level 1 certified processors.
M-Pesa & Airtel Money
Mobile money flows through licensed payment aggregators. Eventia stores only the last 4 digits of a phone number.
Fraud detection
Every purchase is screened by our real-time fraud model. Suspicious transactions are blocked before charge.
Secure authentication
Passwords are hashed with bcrypt. We support OTP-based two-factor authentication via SMS or email.
Data encryption at rest
All database volumes are encrypted at rest using AES-256. Backups are also encrypted and stored in separate regions.
Regular penetration testing
We commission independent security audits and penetration tests at least twice yearly.
Vulnerability disclosure
If you find a vulnerability, please report it to security@eventia.africa. We acknowledge reports within 24 hours.
Responsible disclosure
Found a security vulnerability? We take every report seriously and will work with you to resolve it quickly. We do not pursue legal action against researchers who follow responsible disclosure guidelines.
Report a vulnerabilityGeneral support: Contact us