Built for the operators who trust us with the night.
Your event data — guests, contracts, finance, comms — is the most sensitive information your business handles. Ventra is engineered so it stays that way.
AES-256 at rest. TLS 1.3 in transit. Per-field encryption for payment and identity fields.
Data lives in AWS eu-west-2 and eu-central-1. Backups are geo-redundant within that boundary.
SSO via Google, Microsoft and SAML. Mandatory 2FA for staff. Least-privilege internal access, audited monthly.
Every read and write of sensitive data is logged and retained for 12 months, exportable via API.
Quarterly external penetration tests. Continuous vulnerability scanning. Bug bounty run through Intigriti.
SOC 2 Type II. ISO 27001. UK Cyber Essentials Plus. Reports available under NDA.
- · Zero-trust internal network with mTLS between every service.
- · Secrets stored in AWS KMS with automatic rotation and per-region isolation.
- · Every deployment is signed, immutable and roll-back-tested.
- · Real-time anomaly detection on authentication and API traffic.
- · Disaster-recovery drills every quarter with published RTO/RPO targets.
- · Data Protection Officer on staff. Security committee meets monthly.
- · Every new engineer completes secure-coding and OWASP training in week one.
- · All third-party sub-processors reviewed annually and listed publicly.
- · Privacy by design reviewed at the spec stage of every new feature.
Found a vulnerability? Tell us.
We reward every valid finding and publish an acknowledgements page for researchers who report responsibly. Bounties range from £250 for low-severity to £15,000 for critical, no strings attached.
security@theventra.co