Event app security checklist
The security and privacy questions to ask an event app vendor, what a good answer sounds like, and the four that most often stall a purchase in review.
The short answer
Ask five things first: where attendee data is stored, how long it is kept, who inside the vendor can see it, whether it is used for anything beyond your event, and how an attendee gets their own data deleted. Those five stall more purchases in security review than every technical control combined.
- Data location and retention are what your reviewer will ask. Get them in the RFP.
- An attendee list is personal data whatever your industry calls it.
- Ask what the vendor does with your data after the event ends.
- Vendor answers vary wildly. Ask in writing and keep the answer.
- Written by
- The event67 team
- Last updated
- Length
- 1,300 words, about 11 minutes
Event app security checklist
Security review is where event app purchases stall, and it usually stalls late — after the decision, after the budget, sometimes after the contract. The fix is to ask the five questions below in the written round rather than in month three.
This is a buyer’s checklist, not a technical audit. It is written for the organizer who has to get a purchase through somebody else’s review, and it is honest about our own gaps where they exist.
The five that stall purchases
Ask these first, in writing, of every vendor on your shortlist.
1. Where is attendee data stored? Name the country or region. Not “the cloud”, not “securely”. If your organization has a data residency requirement, this is a yes or no question and it eliminates vendors quickly.
2. How long is it kept, and what happens at the end? A retention period with an end date. “Indefinitely” is an answer, and it is one your reviewer will have views about. Ask specifically whether data is deleted, anonymised, or simply left in place.
3. Who at the vendor can see it? Some support access is normal and necessary. What you want to know is whether it is role-limited, whether it is logged, and whether it requires a ticket from you.
4. Is it used for anything beyond my event? Product analytics, model training, aggregated benchmarks, marketing. Ask plainly. A vendor with a clear answer is easier to get approved than one with a vague one.
5. How does an individual attendee get their data deleted? In-app, by email, or through you. Find out and publish the route, because the request will come.
Those five carry more weight in a security review than any control on the technical list, because they are the questions a reviewer can evaluate without being an engineer.
The full checklist
Work through these with each shortlisted vendor. Score Yes, Partial, No, and record the answer verbatim.
Data handling
- Data centre region named, for both storage and backups.
- Retention period stated, with what happens at the end.
- Deletion path for an individual attendee, and how long it takes.
- Deletion path for the whole event after it ends.
- Whether attendee data is shared with sponsors, and on what legal basis.
- Whether data is used for product analytics or model training.
- Sub-processors listed, with what each one does.
- Data export available to you, in a usable format, before deletion.
Access control
- Distinct administrator roles, with least privilege as the default.
- A moderator role that cannot see the full attendee list.
- Removing a team member revokes access immediately.
- Audit trail of administrative actions, and how long it is kept.
- Vendor support access is role-limited and logged.
- Multi-factor authentication available for organizer accounts.
- Single sign-on, if your organization requires it.
The attendee’s side
- Attendee controls what appears on their own profile.
- Attendee can stay out of the directory entirely.
- Invite links expire, and can be re-issued.
- Attendee can report another attendee, or a photo, and something happens.
- Clear statement to attendees of what is collected, before they join.
- Messaging can be disabled or restricted, per event.
Operations
- Breach notification commitment, with a time frame.
- Independent security assessment or certification, if any, with its date and scope.
- Penetration testing cadence, and whether a summary is available.
- Backup and recovery arrangements.
- Support hours during your event, in your time zone, with an escalation path.
- What happens to your data if you stop being a customer.
Contract
- Data processing terms available and signable.
- Who owns the content you put in, stated explicitly.
- What happens to the app store listing if you change vendors.
- Notice period, and what data you get back.
What a good answer sounds like
Vendor answers in this category vary more than you would expect, and the shape of an answer is informative even before the content.
Good: specific, dated, and volunteered. “Attendee data is stored in [region]. It is retained for [period] after the event ends and then deleted. Support staff can access an event’s data only through a ticket you raise, and that access is logged.”
Acceptable: specific but limited. “We do not currently hold an independent certification. Here is what we do instead, and here is when we expect that to change.”
A warning sign: confident and unfalsifiable. “Enterprise-grade security” and “bank-level encryption” are not answers. Neither is a page of logos. Ask again, and ask for the specific.
A stop: unable to name where the data is. If a vendor cannot say which region holds your attendee list, they cannot help you pass a review.
Where event67 stands
Stated plainly, including the gap, because a security page that only lists strengths is not useful to you.
What is in the product. Multi-tenant separation from the first day of the design, and distinct roles covering platform staff, org super-admins, org admins and per-event moderators. Attendees control what appears on their own profile and can stay out of the directory. Photo moderation runs in admin-only, moderated or open mode, and a reported photo auto-hides pending a decision. Invites are claim-link based, so an attendee’s account exists only when they act.
What is not in the product. There is no in-app account deletion: an attendee asks by emailing privacy@event67.com or through a web page, and the deletion is actioned manually. This is a known gap and we describe it as one. There is also no general audit log: admin chat and billing write an audit record with the actor, and moderation decisions do not — hiding a photo or a question records the new status but not who changed it. And there is no SAML or OIDC single sign-on for organizer accounts; owner and admin accounts are email and password. If either is a hard requirement in your review, score it as absent rather than as partial.
What we do not claim. We do not currently publish an independent security certification, and we will not imply one. If your review requires a specific certification by name, ask us directly and we will tell you whether we hold it rather than pointing at a page of badges.
The three questions organizers forget
“What happens to my data if I leave?” Ask before you sign, not at renewal. The answer determines whether changing vendors is a migration or a restart.
“Who owns the app store listing?” If the app is published under the vendor’s developer account, the listing and its install base belong to them. This is a commercial question that arrives dressed as a technical one, and it is covered in the RFP template.
“What does the vendor do with the aggregate?” Many products publish benchmark statistics derived from customer events. That may be entirely fine with you. It is worth knowing rather than discovering.
Before your review meeting
Bring four things and most reviews go quickly:
- The vendor’s written answers to the five questions at the top of this page.
- The data processing terms, signed or ready to sign.
- A one-line statement of what data the app will hold and for how long.
- The deletion path, written in the words you will use to your attendees.
If you have those, the meeting is a confirmation. If you do not, it is a discovery session, and discovery sessions are where timelines go.
What it costs
- Free up to 50
- activated attendees, on one live event
- $5
- per activated attendee beyond 50
- $4,750
- the most one event can ever cost, whatever happens past 1,000
Activated means the person claimed their invite and opened the app. Not when you import them, not when the invite is delivered, and not if they register and stay home.
Questions people actually ask
What data does an event app collect?
At minimum a name and an email address for every attendee, plus whatever the attendee adds to a profile and whatever the app records about their behaviour: sessions saved, questions asked, connections made, check-in times. Ask the vendor for the full list rather than assuming it stops at the profile.
What should I ask an event app vendor about security?
Where data is stored, how long it is retained, who at the vendor can access it, whether it is used for anything beyond your event, how deletion works for an individual attendee, whether there is an independent security assessment, and what the breach notification commitment is. Get all seven in writing.
Is an attendee list personal data?
Yes. Names, email addresses and anything tied to an identified person are personal data under most privacy regimes, and the fact that attendance is a business activity does not change that. Treat your attendee list as regulated data whatever your industry calls it internally.
How do I handle an attendee who wants their data deleted?
Know the path before anyone asks. Some vendors offer in-app deletion, some require an email to a named address, some require you to raise it. Find out which and publish the route to your attendees, because a request you cannot action quickly becomes a complaint.
Does event67 offer in-app account deletion?
No, and this is a known gap rather than a design choice. Deletion is handled by emailing privacy@event67.com and through a web page. If in-app deletion is a hard requirement for your review, score it as absent.
Keep reading
Ask us the five questions
Roles, a moderator who cannot see everything, and two named gaps: moderation is not audit-logged, and there is no in-app account deletion.