Skip to main content
    Back to Home

    Security

    Last updated: October 2, 2026

    PCI-Compliant Payments

    Payment processing through Stripe (Level 1 PCI compliant)

    Encrypted Data

    All data encrypted in transit and at rest

    Enterprise Infrastructure

    Hosted on enterprise-grade cloud infrastructure

    1. Our Commitment to Security

    At KingdomTix, security is foundational to everything we do. We understand that you trust us with sensitive information—personal data, payment details, and event information—and we take that responsibility seriously. This page outlines our security practices, certifications, and the measures we take to protect your data.

    2. Payment Security

    2.1 PCI DSS Compliance

    All payment processing is handled by Stripe, a PCI Level 1 Service Provider—the highest level of certification in the payment industry. This means:

    • Your credit card information never touches our servers
    • All payment data is encrypted and tokenized
    • We only store transaction references, never full card numbers
    • Stripe undergoes annual third-party audits

    2.2 Fraud Prevention

    We employ multiple layers of fraud prevention:

    • Real-time transaction monitoring
    • Stripe Radar for machine learning-based fraud detection
    • Velocity checks to detect unusual purchase patterns
    • Device fingerprinting for suspicious activity detection
    • Manual review processes for high-risk transactions

    3. Data Protection

    3.1 Encryption

    Encryption in Transit

    All data transmitted between your browser and our servers uses TLS 1.3 encryption (HTTPS). We enforce HSTS to prevent downgrade attacks.

    Encryption at Rest

    All stored data is encrypted using AES-256 encryption. Database backups are also encrypted.

    Key Management

    Encryption keys are managed through secure key management services with automatic rotation.

    3.2 Data Access Controls

    • Row-Level Security (RLS): Database policies ensure users can only access their own data
    • Principle of Least Privilege: Employees only have access to data necessary for their role
    • Audit Logging: All data access is logged and monitored
    • Multi-Factor Authentication: Required for all administrative access

    4. Infrastructure Security

    4.1 Cloud Infrastructure

    Our platform is hosted on enterprise-grade cloud infrastructure that provides:

    • Data centers operated by major cloud providers that maintain their own independent security certifications
    • Geographic redundancy with automatic failover
    • DDoS protection and mitigation
    • Web Application Firewall (WAF)
    • Continuous vulnerability scanning

    4.2 Network Security

    • Network segmentation and firewalls
    • Intrusion detection and prevention systems
    • Regular penetration testing
    • 24/7 security monitoring

    4.3 API Security

    • Rate limiting to prevent abuse
    • JWT-based authentication
    • Input validation on all endpoints
    • CORS policies to prevent unauthorized access

    5. Application Security

    5.1 Secure Development

    • Security-focused code reviews
    • Static application security testing (SAST)
    • Dynamic application security testing (DAST)
    • Dependency vulnerability scanning
    • Regular security training for developers

    5.2 Authentication & Authorization

    • Secure password hashing using bcrypt
    • Account lockout after failed login attempts
    • Session management with secure tokens
    • Role-based access control (RBAC)
    • Optional two-factor authentication

    6. Ticket Security

    6.1 Anti-Fraud Measures

    • Unique QR Codes: Every ticket has a cryptographically secure, unique code
    • One-Time Scan: Tickets are invalidated after check-in
    • Real-Time Validation: QR codes are validated against our database in real-time
    • Transfer Tracking: Complete audit trail for all ticket transfers

    6.2 Scalping Prevention

    • Purchase limits per customer
    • CAPTCHA protection on high-demand events
    • Velocity detection for bulk purchases
    • Account verification requirements

    7. Compliance

    GDPR

    We support GDPR data subject rights, including access, correction, and deletion requests

    CCPA

    We support CCPA/CPRA rights and honor Global Privacy Control opt-out signals

    PCI DSS

    Payment processing through PCI Level 1 compliant provider

    ADA

    We work toward WCAG 2.1 AA accessibility and welcome reports of barriers

    8. Incident Response

    We have a comprehensive incident response plan that includes:

    • 24/7 security monitoring and alerting
    • Defined escalation procedures
    • Incident containment and remediation processes
    • Communication protocols for affected users
    • Post-incident analysis and improvement

    In the unlikely event of a data breach, we will notify affected users within 72 hours as required by applicable regulations.

    9. Vulnerability Disclosure

    We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:

    Security Team

    Email: support@kingdomtix.org

    Please include detailed steps to reproduce the vulnerability. We will acknowledge receipt within 24 hours and work with you to address the issue.

    10. Security Best Practices for Users

    We recommend the following security practices:

    Use Strong Passwords

    Create unique passwords with at least 12 characters including letters, numbers, and symbols.

    Beware of Phishing

    We will never ask for your password via email. Always verify emails come from @kingdomtix.org.

    Enable Two-Factor Authentication

    Add an extra layer of security to your account (available in account settings).

    Keep Software Updated

    Ensure your browser and devices are running the latest security updates.

    11. Important Disclaimer

    This page describes our security practices for informational purposes only. It is not a warranty, guarantee, or contractual commitment, and it does not constitute a certification of any third-party standard on our behalf. No system can be made completely secure. Our practices may change as the platform evolves, and any references to third-party providers describe their published programs, not ours. Nothing on this page expands the obligations or liability set out in our Terms of Service, which continue to apply in full, including the limitation of liability. Security of events, venues, staffing, and on-site safety is the responsibility of the event organizer.

    12. Contact Security Team

    For security-related questions or concerns, please contact us:

    KingdomTix Security Team

    Email: support@kingdomtix.org

    For vulnerability reports: support@kingdomtix.org