Skip to content
EventStack

Trust Center

Clear security posture for public beta teams.

EventStack labels implemented controls and roadmap items honestly. Formal compliance certifications are roadmap, not launch claims.

Security overview

Implemented

Documented boundary control in the EventStack core runtime.

Tenant isolation

Implemented

Documented boundary control in the EventStack core runtime.

API-key handling

Implemented

Documented boundary control in the EventStack core runtime.

Session handling

Implemented

Documented boundary control in the EventStack core runtime.

Event auditability

Implemented

Documented boundary control in the EventStack core runtime.

Public redaction behavior

Implemented

Documented boundary control in the EventStack core runtime.

Data retention

Implemented

Documented boundary control in the EventStack core runtime.

Data export and deletion requests

Implemented

Documented boundary control in the EventStack core runtime.

Payment processing through Stripe

Vendor-Hosted

Handled through the named vendor integration rather than stored directly by EventStack.

Transactional email through Postmark

Vendor-Hosted

Handled through the named vendor integration rather than stored directly by EventStack.

Subprocessors

Disclosed

Current vendor dependencies are disclosed without claiming EventStack certification.

Security contact

Published

Security reports route to the published EventStack security contact.

Roadmap disclosures

  • MFA Enforcement Planned
  • SAML SSO Planned
  • SOC 2 compliance Roadmap
  • Data residency controls Roadmap

Security contacts

For vulnerability reports, security policies, and custom compliance check requests:

security@useeventstack.app

Launch limitations

  • MFA enforcement and SAML SSO are not available in early access.
  • Public status and changelog pages are read-only projections from backend data.
  • Replay is designed for preview-first operation and requires explicit confirmation outside local-only flows.
  • Single-node Compose or K3s deployments are not high-availability unless operators deploy the documented HA topology.
  • Plan limits are the event, API-call, and workflow limits published on the pricing page.
  • Formal compliance certifications and data-residency controls are roadmap items, not launch claims.