May 18, 2025 | 3 min read
Overview
Eventact is a multi-tenant SaaS platform built for comprehensive event management. It serves event organizers,
conference planners, exhibitor coordinators, and recreation organizers,
offering a secure and efficient solution for managing events.
System Interfaces
Event Organizers – Use the Back Office to set up events, create registration forms, manage pricing, configure event websites, send emails and SMS, manage apps, import/export data, delete records, and control system access.
Event Participants – Register for events, use event applications, browse event websites, and submit abstracts or other materials.
Potential Event Participants – Access public event information through event websites and promotional emails.
Terminology
- Back Office – The administrative backend for managing events, attendee monitoring, and system configurations.
- Admins – Back Office users with varying permission levels, from limited operators to security administrators.
- Users – Individuals registering, participating in events, or submitting content (e.g., abstracts).
Server Protection
-
All traffic is encrypted using HTTPS with TLS 1.2 or higher.
-
URL filtering blocks requests containing harmful characters, unsafe file extensions, suspicious segments, and known malicious user-agents.
-
Web server logs store IP addresses and timestamps for audit and security purposes.
Data Center Protection
Physical Protection
-
Hosted in a Tier 3 redundant server facility in Israel.
-
The facility includes 24/7 CCTV monitoring and restricted access limited to authorized Eventact personnel.
-
All infrastructure is owned and controlled directly by Eventact, not shared in a public cloud environment.
Power and Environmental Protections
- Redundant power (N+1), dual power supplies on servers and network components.
- Backup generators ensure 72 hours of runtime during outages.
- Fire suppression (FM200) and flood detection systems are active and monitored around the clock.
Water and Fire Damage Protection
- The facility has controlled fire suppression and detection systems that are monitored 24/7.
- The server farm is equipped with a comprehensive flood detection system, including water leak sensors and drainage monitoring, to protect against potential water damage.
Back Office Access Protection
Admins Password Policy
- Configurable Minimum 8 to 40 characters including complexity rules such as uppercase, lowercase, numbers, and special characters requirement.
- Common words and sequences count as one character.
- Passwords expire after 60 days; reuse of previous passwords is not allowed.
-
Two-factor authentication is required for new devices/browsers.
- Five failed login attempts result in a 20-minute IP lockout.
- Accounts are locked after 45 days of inactivity.
- Inactive sessions auto-disconnect after 20 minutes.
- Passwords are stored in encrypted format.
- Back Office access is restricted to HTTPS only.
Access Monitoring and Control
-
All login attempts are logged.
-
Customer security admins can manage users and monitor access.
- Access restrictions can be applied by IP and country.
- Email alerts are sent for failed login attempts and access from new devices.
- User roles and feature access are customizable.
Predefined User Roles
- Security Admin – Manages user access and receives security alerts.
- Director – Receives event summary reports.
- Bookkeeper – Access to financial summaries and transactions.
- Billing Contact – Receives billing notifications.
- Company Admin – Can create new projects.
- Project Admin – Can configure project settings.
- Power Operator – Can delete data.
- Operator – Can edit data and manage attendees.
Remote Access Protection
Remote Server Access
- Remote access is permitted only from the Eventact offices and restricted to authorized personnel.
Firewall Security
- Eventact owns and manages its firewall infrastructure.
- Firewall access is restricted and logged with immediate alert generation.
- Logs are stored both locally and in the cloud.
Network Segmentation
- Internal segmentation is implemented to isolate the database server from the application server, minimizing lateral threat movement.
Continuous Security Maintenance
- Regular OS and firewall updates.
- Active antivirus software on all servers.
- Vulnerability scans conducted by a PCI Approved Scanning Vendor (ASV).
Log Retention
-
Logs are retained per compliance and audit requirements to support investigations:
- Web Server Logs: 1 year
- Firewall Logs: 1 week (extendable to 1 year upon request)
Incident Response Plan
Security incidents are actively monitored, and suspicious activities trigger alerts.
Eventact maintains a formal Incident Response Plan (IRP), which includes:
- Identification – Detecting suspicious activity via monitoring systems.
- Containment – Isolate affected systems to prevent spread.
- Eradication – Remove the threat.
- Recovery – Restore normal operations.
- Review – Post-incident analysis and improvements.
Data Backup & Disaster Recovery
-
Daily backups are performed according to Eventact's internal policies.
- Weekly off-site backups are retained for one month.
- Optional dedicated environments with custom backup policies are available.
-
Disaster Recovery Objectives:
- RTO (Recovery Time Objective): 4 hours
- RPO (Recovery Point Objective): 24 hours
End User Data Protection
Data Ownership & Privacy
- Customers (event admins) are the data owners and Data Controllers under GDPR.
- Eventact operates as a Data Processor, providing tools to support compliance.
Data Collection & Validation
- Data collection is controlled by the event admin.
- Eventact provides tools to view and delete collected data.
-
Data validation includes:
- Required field checks
- Format validation (e.g., emails, phone numbers)
- Length and input restrictions
- Protection against XSS and SQL injection
User Authentication & Protection
- Authentication options include password or OTP (via email/SMS), configurable by the organizer.
- Google Enterprise reCAPTCHA can be enabled to block bots.
- Accounts are locked after four failed login attempts.
- Users are auto-logged out after 20 minutes of inactivity.
- All user activity is logged and retained until the user is deleted.