TRUST & SECURITY

Enterprise-grade security for every event you run.

Zuddl protects attendee, sponsor, and organizer data across every stage of the event lifecycle — from registration and engagement to onsite experiences — backed by independent audits and a continuously monitored security program.

Zuddl security shield
5+
Certifications
SOC 2 II
Annual audit
AES 256
Encryption at rest
TLS 1.2+
Encryption in transit
60m
Recovery Time Objective
24/7
Continuous monitoring

Independently audited.Continuously validated.

Zuddl's security and privacy program is independently audited and aligned with globally recognized standards. Every certification here is current and in-scope for the Zuddl SaaS platform.

SOC 2 Type II

Security, Availability, and Confidentiality Trust Services Criteria for the Zuddl platform.

Request Report

ISO/IEC 27001:2022

Information Security Management System (ISMS) certification. Current 2022 revision.

View in Trust Center

ISO/IEC 27701:2019

Privacy Information Management System (PIMS) extending our ISO 27001 certification.

View in Trust Center

GDPR

Aligned with EU data protection requirements. SCCs in place for international transfers.

Download DPA

CCPA / CPRA

Aligned with California privacy and consumer data protection requirements.

View Privacy Rights

CSA CAIQ Lite

Cloud Security Alliance self-assessment covering cloud security controls.

View in Trust Center

Need a specific framework for your review? Contact security@zuddl.com

Security built into every layer.

Zuddl follows a defense-in-depth approach with controls across infrastructure, application, data, identity, and operations — validated by independent audits.

Hardened cloud, segregated environments

Hosted on AWS with logically separated environments. Infrastructure regularly patched and monitored. Geographically separated backup and DR setup.

AWS with environment segregation
Infrastructure regularly patched & monitored
Geographically separated backup & DR

Secure by design, tested by independents

Every code change passes through our SSDLC: code reviews, static analysis and dependency scanning (Snyk), and annual third-party penetration testing.

SSDLC with code reviews
Static analysis & dependency scanning
Annual third-party penetration testing

Encrypted, classified, retained on your terms

AES-256 at rest, TLS 1.2+ in transit. Encryption key management via AWS. Data retention aligned to contract; secure deletion on request.

AES-256 at rest, TLS 1.2+ in transit
Key management via AWS
Retention per contract; deletion on request

Identity and access, least privilege by default

SSO via SAML, MFA support, and role-based access control. Access is granted on least-privilege principles and reviewed on a regular cadence.

SSO (SAML) and MFA support
Role-based, least-privilege access
Periodic access reviews

Monitored operations, ready for incidents

Continuous monitoring with audit logging across admin activity, plus a documented incident response process and defined customer notification timelines.

24/7 monitoring and audit logging
Documented incident response plan
Defined customer notification timelines

Built for the realities of live events.

Zuddl handles event-specific risks that traditional SaaS platforms don't address — peak traffic, attendee PII, live streaming, onsite check-in, and multi-party data sharing.

Reg & attendee data

Attendee data processed per customer, segregated per event, with strict access controls.

Video & streaming security

Live video delivered securely with encryption, origin isolation, and per-attendee authentication controls.

Onsite check-in & mobile

Secure device data transmission with offline storage, syncing safely when connectivity is restored.

Lead capture & sharing

Data sharing controlled by configuration, with role-based access and audit logging.

Multi-tenant architecture

Customer data logically segregated, with strict access controls ensuring isolation between all tenants.

AI governance

AI features are opt-in, with no external training and strict data usage boundaries.

Responsible AI, with clear boundaries.

Zuddl uses AI to power features like the AI Content Hub and Zuddl AI Agents. Customer data is never used to train external models, and every AI feature is governed by our AI System Development and Evaluation Policy.

Data isolation

Customer content stays within Zuddl's processing boundary. No customer data trains external model weights.

Governance

AI features developed under policies aligned with SOC 2 and ISO 27701 controls. DPIAs for all new AI features.

Oversight

Human review for AI outputs impacting customer data. AI Governance Committee oversees integration.

Controls

AI features are opt-in. Customers control enablement at the workspace level. All AI providers bound by DPAs.

Read our AI governance disclosures in the Trust Center

Your data. Your control.

Zuddl acts as a data processor on behalf of customers. We support your obligations under GDPR, CCPA/CPRA, and other privacy frameworks.

Our commitments
Resources
GDPR-aligned data processing across all services
Data Processing Agreement (DPA)
Standard clauses for secure international transfers
Sub-processor list
EU data residency available upon request
Privacy Policy
Data request support: access, deletion, portability
CPRA notice
Transparent sub-processors with advance notice
GDPR compliance
Defined retention, followed by secure data deletion
Data subject request

Enterprise-ready controls.

Zuddl gives your security and IT teams the controls they expect from enterprise software.

Identity

SSO (SAML via WorkOS)
MFA support

Governance

Retention aligned to contract
Secure deletion on request
Cookie & consent management

Visibility

Audit logs for admin activity
Exportable logs

Access

Role-based access control
Event-level permissions
Team-based access

Designed for reliability.

Live events don't wait for maintenance windows. Our resilience architecture is built for uninterrupted operation and rapid recovery. Zuddl maintains business continuity procedures aligned with ISO 27001. Backups are stored in geographically separated regions. Improved RPO targets available for enterprise deployments.

60 min
Recovery Time Objective
≤ 24 hr
Recovery Point Objective
Daily
Verified Backups
Geo
Separated DR Regions
ISO
27001 aligned BCMS

View live status → status.zuddl.com

Trust extends to our ecosystem.

Sub-processors are reviewed before onboarding. Security and data handling requirements are contractually enforced. Vendors are periodically reassessed.

Report a vulnerability.

Security researchers are a critical part of our program. If you discover a security issue, we want to know.

Email security@zuddl.com with:

Description of the issue
Steps to reproduce
Potential impact
Your contact information (optional)

Everything your review needs.

Four paths, one place. Pick the one that fits where you are in your review.

Visit theTrust Center

Certifications, policies, pentests, sub-processors, questionnaires.

View in Trust Center

Request AuditReports

SOC 2 Type II, ISO 27001:2022, and ISO 27701:2019 under NDA.

View in Trust Center

HigherSatisfaction

Our Data Processing Agreement, ready for your legal team.

Download DPA

EnhancedEngagement

Send your CAIQ, SIG, or custom questionnaire.

security@zuddl.com

Common questions.

Where is customer data stored?
Zuddl uses AWS infrastructure, with primary hosting in the US and geographically separate backups. EU data residency is available on request.
How long is customer data retained?
Retention is aligned to your contract. On request, we securely delete customer data within the timelines defined in the agreement.
Does Zuddl use customer data to train AI models?
No. Customer content stays within Zuddl's processing boundary and is never used to train external model weights.
How are sub-processors vetted?
Sub-processors are security reviewed before onboarding, contractually bound to our data handling requirements, and periodically reassessed.
What is your incident notification process?
We maintain a documented incident response plan with defined customer notification timelines, in line with contractual and regulatory obligations.
Do you support SSO and MFA?
Yes. SSO is supported via SAML (WorkOS) and MFA is available for workspace accounts.
Can I get audit logs for my workspace?
Yes. Admin activity is captured in audit logs, and logs are exportable for your own monitoring and review.
How is payment data protected?
Payment processing is handled by PCI-compliant payment providers. Zuddl does not store full card numbers.
What's your RTO and RPO?
Our Recovery Time Objective is 60 minutes and our Recovery Point Objective is 24 hours or less. Improved RPO targets are available for enterprise deployments.
How can I request a pentest report or SOC 2 report?
Request them through the Trust Center, or email security@zuddl.com. Reports are shared under NDA.

Built for enterprise scale and enterprise security.

Zuddl meets global privacy standards, including GDPR, CCPA, SOC 2, and ISO, ensuring transparency and lawful data handling. Our security measures follow industry best practices for data protection and risk management.

GDPR, CCPA, AICPA SOC 2 and ISO compliance badges
Questions about security?Our team is here to help.