Enterprise grade security & data protection
At Lanternfly, data security and privacy are paramount — built around widely used security frameworks such as ISO 27001 and SOC 2 controls, with GDPR-ready data handling.
Security built in
Our controls are reviewed regularly. Our security pack is available for enterprise reviews.
Request the security packHow we protect your events
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest, and encrypted backups across regions — with keys rotated on schedule.
Access by design
SSO/SAML, role-based permissions, audit logs and automatic session controls on every workspace.
Resilience tested
Offline-capable check-in, redundant streaming ingest and disaster-recovery drills before peak season.
Privacy by default
Data residency options, retention controls and opt-out tooling for GDPR, PDPA and beyond.
Secure development
Peer-reviewed code, dependency scanning, penetration tests and a managed bug-bounty intake.
Vendor diligence
Every sub-processor is reviewed annually and listed in our data protection documentation.
Vulnerability disclosure policy
Found a security issue? We want to hear from you — and we commit to responding quickly and fairly.
How to report
Email security@lanternfly.events with a description, steps to reproduce and the impact you observed. Encrypted reports are welcome — request our PGP key in the same inbox.
What happens next
We acknowledge within 48 hours, triage within 5 business days, and keep you updated until the issue is resolved. We ask that you give us reasonable time to fix before any public disclosure.
Ground rules
Please avoid accessing other customers' data, degrading service availability, or social-engineering our team. Research within these bounds will never result in legal action from us.
Recognition
With your permission, we credit reporters in our release notes and maintain a hall of thanks for significant findings.
Need our security pack?
Certificates, pen-test summaries and sub-processor lists for your review.
Contact us