Eventlify maintains organizational, technical, and administrative measures designed to protect financial account information against unauthorized access, destruction, loss, alteration, or misuse. We leverage the infrastructure of our payments partner, Stripe. Stripe is the leading payments service provider in the world. They are a certified PCI Service Provider Level 1. This is the most stringent level of certification available in the payments industry.
The credit cards that are entered through our system are not maintained on our (Eventlify’s) system. Once entered, they are encrypted at rest with AES-256 and stay on Stripe’s server. Decryption keys are stored on separate machines. None of Stripe’s internal servers and daemons can obtain plain text card numbers but can request that cards are sent to a service provider on a static allowlist. Stripe’s infrastructure for storing, decrypting, and transmitting card numbers runs in a separate hosting environment.
Stripe forces HTTPS for all services using TLS (SSL), including our public website and your event registration page.
In particular, all data associated with financial accounts is encrypted in transit and at rest. Because of the sensitive nature of this information, it is also protected by additional access controls, along with ongoing monitoring to prevent data misuse.