Security

How we protect your plans and your guests

Written for the person doing vendor diligence — including what we don't have yet.

Accounts and access

Passwords are stored as salted bcrypt hashes — never in plain text, and never recoverable by us. Sessions use signed, expiring tokens in HTTP-only cookies. All traffic is HTTPS. Every workspace is isolated: each query is scoped to your organization, so one customer's data is never reachable from another's session.

Share links

A share link is authorized by a long, unguessable token — not a sequential id — and every shared page is explicitly excluded from search-engine indexing. You control the permission level (view, comment, or copy) and can enable an email gate so you know who opened the plan. Anyone with the link can see what it points to, so treat links like the documents they contain; you can rotate or revoke them at any time.

Guest and attendee data

Attendee names, emails, meal choices, and notes are treated as your content. They're used only to render your seating and exports, are never sold, never used to train AI models, and are deleted when you delete them or your account. Emails captured by a share link's email gate belong to the diagram owner's workspace — not to us.

Infrastructure

The application and database run on managed cloud infrastructure with encryption in transit, automated backups, and access limited to the people who operate the service. Transactional email is sent through a dedicated provider under standard data-processing terms. We keep the processor list current in our Privacy Policy.

Getting your data out — in writing

Exports are available on every plan, including Free, and are never paywalled: PDF, image, and data exports of your diagrams. If we ever discontinue the service we commit to at least 90 days' notice with exports available throughout (Terms §9), and our migration guarantee — concierge conversion, 60-day parallel use, and a clean exit with your files — is written into Terms §10. Independence is the product; we hold ourselves to it on the way out too.

Where we are today — honestly

EventDiagram is an early-stage product built by a small team in Phoenix, Arizona. We are not SOC 2 certified today, and we won't claim a badge we haven't earned. What we offer instead is architectural honesty: tenant isolation, hashed credentials, noindexed share links, open exports, and a written wind-down commitment — plus a direct line to the people who build it. If your procurement process needs a security questionnaire completed, send it over and we'll answer it truthfully, including the parts where the answer is “not yet.”

Reporting a vulnerability

Email security@eventdiagram.com with details and reproduction steps. We'll acknowledge quickly, keep you updated, and credit you if you'd like. We won't pursue legal action against good-faith research that avoids privacy violations, data destruction, and service disruption.

Questions a security review needs answered? Contact us — a person answers.