Trust & safety

Security at EventNaija

Events involve real money, real dates and personal details. This page explains the controls that protect clients and vendors, and the responsibilities we share with you.

This page is maintained by the EventNaija team and describes our own practices. It is not an independent certification or audit. Online payments are not live yet, so payment controls describe how funds will be handled once our payment provider is enabled.

Two-factor authentication

Accounts can require a one-time code in addition to a password, so a leaked password alone cannot open an account. Vendors handling paid bookings are strongly encouraged to keep it on.

Encrypted payment data

Payments run through a licensed payment provider. Card numbers are never typed into or stored by EventNaija — we keep only a reference to the transaction, and all traffic is encrypted in transit with TLS.

Role-based permissions

Clients, vendors and staff see only what their role allows. A vendor can read the briefs sent to them and nothing else; support access is limited and separated from ordinary accounts.

Fraud detection

Sign-ups, quotes and payments are screened for known fraud patterns — duplicate identities, off-platform payment pressure, mismatched details and unusual booking velocity. Flagged accounts are reviewed before payouts.

Audit logs

Quote, payment, booking and permission changes are recorded with a timestamp and actor. If a dispute arises, there is a traceable record of who changed what and when.

Secure file storage

Portfolios, briefs and contracts are stored in access-controlled storage with signed, expiring links, so files are not publicly guessable URLs.

Automatic backups

Booking and messaging data is backed up on a regular schedule with point-in-time recovery, so an incident does not lose your event records.

Payment-gated messaging

In-platform messaging opens once a booking is confirmed. Keeping conversations on EventNaija keeps agreements, changes and delivery on the record for both sides.

What we ask of you

  • Use a unique password and turn on two-factor authentication.
  • Keep quotes, payments and changes inside EventNaija — off-platform payment requests are a red flag.
  • Never share one-time codes with anyone, including someone claiming to be EventNaija support.
  • Report anything suspicious to support@eventnaija.com so we can review the account.

Report a vulnerability

Found a security issue? Email security@eventnaija.com with the details and steps to reproduce. We acknowledge reports within two business days and will not pursue good-faith researchers.