Skip to content

Security at Eventia

Your money and your data deserve real protection. Here's exactly how we keep them safe.

TLS everywhere

All data in transit is encrypted with TLS 1.3. We enforce HSTS and DNSSEC on all domains.

PCI-DSS compliant payments

Card data never touches our servers. All card processing is handled by PCI-DSS Level 1 certified processors.

M-Pesa & Airtel Money

Mobile money flows through licensed payment aggregators. Eventia stores only the last 4 digits of a phone number.

Fraud detection

Every purchase is screened by our real-time fraud model. Suspicious transactions are blocked before charge.

Secure authentication

Passwords are hashed with bcrypt. We support OTP-based two-factor authentication via SMS or email.

Data encryption at rest

All database volumes are encrypted at rest using AES-256. Backups are also encrypted and stored in separate regions.

Regular penetration testing

We commission independent security audits and penetration tests at least twice yearly.

Vulnerability disclosure

If you find a vulnerability, please report it to security@eventia.africa. We acknowledge reports within 24 hours.

Responsible disclosure

Found a security vulnerability? We take every report seriously and will work with you to resolve it quickly. We do not pursue legal action against researchers who follow responsible disclosure guidelines.

Report a vulnerability

General support: Contact us