Eventloom

Version 2026-07-22-beta · Pre-launch legal review required

Security and Responsible Disclosure

How Eventloom protects the service and receives vulnerability reports.

Safeguards

Eventloom uses tenant authorization, multi-factor authentication for sensitive creator operations, encrypted provider transport and storage, minimized logging, rate limits, signed webhooks, dependency scanning, backups, and monitored production changes.

Report a vulnerability

Send a concise report with affected URL, reproduction steps, impact, and contact information to the security contact. Do not access other people’s data, degrade the service, use social engineering, or publicly disclose an unresolved issue. A safe-harbour statement and production security mailbox will be finalized before launch.

This pre-launch document records the intended product rules. It is not represented as lawyer-approved. Paid public launch remains disabled until Ontario/US legal review and the final business identity and contact details are published.