Technical Systems, Security & Compliance
Built to satisfy the most demanding procurement and audit reviews. Explore how Its1Ticket delivers enterprise cloud reliability, strict FERPA-grade data privacy, SAQ A PCI isolation, and financial auditability.
1. Cloud Architecture & Serverless Reliability
Built on serverless edge computing with zero physical server maintenance on your side.
Its1Ticket operates as a modern Software-as-a-Service (SaaS) platform hosted on Vercel’s globally redundant edge network, managed Supabase PostgreSQL databases, and Cloudflare R2 object storage with 11-nines annual durability.
Zero Local Footprint
No on-premise server hardware, local SQL Server installations, or IIS web hosting required. All releases and patches deploy centrally with zero downtime.
Atomic Row-Locking Concurrency
High-demand on-sale ticket releases execute as atomic database transactions with row-level locking. Overselling is structurally impossible even during massive traffic spikes.
Offline-First Gate & POS Operations
Gate scanning and point-of-sale registers operate fully offline during venue Wi-Fi or cellular failure, validating tickets locally with cryptographic QR signatures and syncing automatically on reconnect.
2. Attendee Privacy & Data Stewardship
Every account is held to the strictest standard any of our customers is subject to.
Unlike consumer event platforms that sell attendee data or run advertising, Its1Ticket never sells, markets, or trains AI models on your data. For customers covered by FERPA, we also act strictly as a "School Official" under 34 C.F.R. § 99.31.
Attendee Photo Auto-Purge
Attendee photos captured for digital ticket verification are automatically and permanently purged by scheduled sweep within 3 days after event completion (and no later than 7 days post-capture).
Sensitive Field Access Logging
Custom registration fields marked as sensitive (e.g. medical notes) generate visual safety badges and write permanent entries to an append-only audit log whenever viewed by staff.
Zero AI/ML Model Training
Attendee records, purchase histories, and registration responses are contractually excluded from any third-party or general-purpose LLM / AI training sets.
3. PCI Compliance & Payment Scope Isolation
Keeping your network out of PCI scope via Stripe’s Level 1 certified payment elements.
All credit/debit card transactions are processed through Stripe Elements secure iframe overlays. Payment credentials are tokenized directly on Stripe’s PCI DSS Level 1 servers before touching network environments.
SAQ A Scope Isolation
Because cardholder data is tokenized in isolated browser overlays, your own infrastructure qualifies for SAQ A validation, eliminating complex local PCI auditing burden.
Multi-Channel Support
Native support for Apple Pay, Google Pay, Visa, Mastercard, Discover, Amex, Stripe WisePOS smart card readers, and cash/check reconciliation without extra fees.
Automated Sales Tax Calculation
Integrated calculation of state sales tax and county surtaxes (e.g., Florida 6% state + county surtax) mapped automatically by item category and billing jurisdiction.
4. Enterprise Identity & Role-Based Access (RBAC)
Seamless integration with your identity provider and 5-tier role enforcement.
Staff authenticate using their existing organization credentials via Single Sign-On (SSO). System permissions are strictly enforced at both application and database Row-Level Security (RLS) layers.
Single Sign-On (OIDC)
Supports federated sign-in via Microsoft Entra ID (Azure AD) and Google Workspace using OpenID Connect protocols. No new staff passwords to manage or store.
5-Tier Role Hierarchy
Granular role-based provisioning: Owner, Admin, Member/Coach, Store Manager (isolated store access with no ticketing access), and Gate & Store Scanner.
Time-Boxed Gate Pairing
Gate scanning devices are paired via secure QR codes or 6-digit PINs without account creation. Access is time-boxed and automatically expires after the event.
5. Financial Controls & Auditability
Centralized oversight for finance and audit teams with per-location flexibility.
Its1Ticket enforces strict segregation of duties and maintains immutable, append-only logs for all sales, refunds, voids, inventory adjustments, and administrative report views.
Event Publication Approval Workflow
Standard staff event requests start in draft and route automatically to pending_approval until a verified Owner or Admin explicitly reviews and publishes the event.
Append-Only Audit Logging
Every financial transaction, cashier void, inventory adjustment, and report view/export is permanently attributed to a named user with microsecond timestamps.
Hierarchical Budget Code Mapping
Transactions carry budget codes and general ledger tags for automated export to ERP and accounting systems (such as SAP).
6. Accessibility & Inclusivity (ADA / Section 508)
Ensuring every fan and community member can access event tickets effortlessly.
The fan-facing purchasing and ticket delivery experience is designed following Web Content Accessibility Guidelines (WCAG) 2.1 Level AA and Section 508 accessibility standards.
Keyboard & Seat-Map Alternatives
Complete keyboard operability across checkout, with a dedicated list-based seat selection alternative for reserved seating events that does not rely on canvas graphics.
Screen Reader ARIA Live-Regions
Polite live-region announcements for seat-hold countdown timers, purchase status changes, and shopping cart updates.
High-Contrast & Dual Signaling
All status indicators pair clear text labels or distinct icons alongside color coding so information is never conveyed by color alone.
Need a Security Questionnaire or Data Privacy Addendum?
View our official Data Privacy Addendum (DPA) directly, or request assistance with a custom security questionnaire.