sbTix

Trust

Last updated 2026-08-05 · This page is for buyers, security reviewers, and procurement teams.

Have a security questionnaire? Our pre-answered CAIQ v4 (197 rows, aligned to the Cloud Security Alliance's Consensus Assessments Initiative) is available under NDA. Ask [email protected]. We respond within 5 business days.

Compliance status

StandardStatusNotes
GDPRLiveData-subject rights endpoints, DPA on request.
CCPALiveSame access + delete rights for CA residents.
PCI DSSInheritedCard data never touches our systems — handled by a PCI DSS Level 1 payment processor.
SOC 2 Type IIQ4 2026 targetReadiness assessment available under NDA. Inherited controls from underlying SOC 2 Type II infrastructure + payment processor documented.
HIPAAEnterprise tierBusiness Associate Agreement available on request for product lines requiring it.
EU AI ActLiveAI-assisted content labeled; model registry maintained.
ISO 27001InheritedInherited from underlying ISO 27001 certified cloud infrastructure.

Sub-processors

sbTix delivers the service through a small set of vetted sub-processor categories, each held to the certifications listed below. The full, named sub-processor list — including contract terms, data residency specifics, and change history — is disclosed in our Data Processing Agreement, provided on request under NDA.

CategoryPurposeData handledMinimum certifications
Cloud infrastructureHosting, edge compute, database, object storage, DNS, WAFAll customer data at rest and in transitSOC 2 Type II · ISO 27001 · PCI DSS
Payment processingCard acceptance, marketplace payouts to organizer accountsPayment card data (never touches our systems), buyer identity for anti-fraud, organizer payout account detailsPCI DSS Level 1 · SOC 1/2 Type II
Transactional emailReceipt delivery, ticket PDFs, magic-link invites, notificationsEmail addresses, ticket PDF contents, receipt line itemsSOC 2 Type II
AI/ML servicesAI-assisted support drafts, planned agent-side automationsSupport ticket text (opt-in per feature) — no card data, no passwords, no session tokensSOC 2 Type II

Adding a new sub-processor category or a new named vendor within an existing category triggers 30 days' notice to affected customers. Enterprise customers can require pre-approval by contract.

Security surfaces

Data handling

Availability

Insurance

Coverage details available under NDA. Certificates of Insurance (COI) issued within 24 hours of request to [email protected].

Contact