Last updated 2026-08-05 · This page is for buyers, security reviewers, and procurement teams.
| Standard | Status | Notes |
|---|---|---|
| GDPR | Live | Data-subject rights endpoints, DPA on request. |
| CCPA | Live | Same access + delete rights for CA residents. |
| PCI DSS | Inherited | Card data never touches our systems — handled by a PCI DSS Level 1 payment processor. |
| SOC 2 Type II | Q4 2026 target | Readiness assessment available under NDA. Inherited controls from underlying SOC 2 Type II infrastructure + payment processor documented. |
| HIPAA | Enterprise tier | Business Associate Agreement available on request for product lines requiring it. |
| EU AI Act | Live | AI-assisted content labeled; model registry maintained. |
| ISO 27001 | Inherited | Inherited from underlying ISO 27001 certified cloud infrastructure. |
sbTix delivers the service through a small set of vetted sub-processor categories, each held to the certifications listed below. The full, named sub-processor list — including contract terms, data residency specifics, and change history — is disclosed in our Data Processing Agreement, provided on request under NDA.
| Category | Purpose | Data handled | Minimum certifications |
|---|---|---|---|
| Cloud infrastructure | Hosting, edge compute, database, object storage, DNS, WAF | All customer data at rest and in transit | SOC 2 Type II · ISO 27001 · PCI DSS |
| Payment processing | Card acceptance, marketplace payouts to organizer accounts | Payment card data (never touches our systems), buyer identity for anti-fraud, organizer payout account details | PCI DSS Level 1 · SOC 1/2 Type II |
| Transactional email | Receipt delivery, ticket PDFs, magic-link invites, notifications | Email addresses, ticket PDF contents, receipt line items | SOC 2 Type II |
| AI/ML services | AI-assisted support drafts, planned agent-side automations | Support ticket text (opt-in per feature) — no card data, no passwords, no session tokens | SOC 2 Type II |
Adding a new sub-processor category or a new named vendor within an existing category triggers 30 days' notice to affected customers. Enterprise customers can require pre-approval by contract.
Coverage details available under NDA. Certificates of Insurance (COI) issued within 24 hours of request to [email protected].