Trust & security
Built with IT, finance and enterprise buyers in mind.
Venue360 handles sensitive venue and guest data. Here's how access, storage and governance are structured.
All claims on this page are reviewed by our technical team and legal counsel before publication, and are kept current as our architecture evolves.
Architecture & access
How data is protected in transit and at rest.
Data ownershipYou own your data. Ownership and access terms are set out in your agreement with Smart Segments.
Hosting architectureCloud-hosted infrastructure with environment separation between customers and between development and production.
EncryptionData is encrypted in transit and at rest using industry-standard protocols.
AuthenticationSecure authentication methods appropriate to each connected system, with credentials never stored in plain text.
Access controlsRole-based access with the principle of least privilege applied across internal and customer-facing systems.
Credential managementSource-system credentials are stored securely and rotated according to platform requirements.
Operations & governance
How we monitor, retain and respond.
Data minimisationOnly the data required for agreed workflows and reporting is collected and retained.
MonitoringOngoing monitoring of system access and data flows to detect and respond to anomalies.
Data retentionRetention periods are agreed per customer and aligned with applicable regulations.
BackupsRegular backups with defined recovery procedures.
Incident responseA defined process for identifying, containing and communicating security incidents.
SubprocessorsA maintained list of subprocessors is available on request.
Regional hostingRegional hosting options are available depending on customer requirements.
Customer offboardingA defined process for data deletion and access revocation at the end of an engagement.
Responsible AIAI features operate on approved, scoped data with human review built into operational actions.
Security enquiries
Need a completed security questionnaire?
Our team can respond to due-diligence and security review requests directly.
