generated: '2026-08-13' method: searched source: >- https://eventx.io/data-protection-and-security + https://eventx.io/llms.txt + https://eventx-hq.gitbook.io/knowledge-base/api-doc/auth + openapi/eventxtra-public-api-openapi.json standards: - id: iso-27001 conforms: true evidence: >- "ISO 27001 Certified" stated on the EventX Data Protection & Security page and homepage; reiterated in the site llms.txt ("ISO 27001 certified", and "first Asia-based event platform to earn this security certification"). source: https://eventx.io/data-protection-and-security - id: gdpr conforms: true evidence: >- "GDPR Compliant" stated on the Data Protection & Security page and homepage; llms.txt states GDPR compliance since 2018; a published sub-processor list is maintained at https://eventx.io/eventx-sub-processor. source: https://eventx.io/data-protection-and-security - id: soc2 conforms: false evidence: No SOC 2 attestation published on the security or compliance pages. - id: openapi conforms: true version: 3.2.0 evidence: >- EventX publishes a machine-readable OpenAPI 3.2.0 document for the Public API at https://esaas-api.eventx.io/api-docs/public-api/openApi.json, linked from its GitBook API reference. 46 paths, 58 operations, all with operationIds and summaries. source: https://esaas-api.eventx.io/api-docs/public-api/openApi.json - id: oauth2 conforms: false evidence: >- No OAuth 2 flow. Authentication is an apiToken-for-JWT exchange (POST /public-api/v1/auth) with the resulting bearer token sent in an Authorization header, declared in the spec as an apiKey security scheme. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any EventX host; every probe returned 404 or an HTML application shell. - id: rfc9457 conforms: false evidence: >- Errors use a bespoke envelope { error: { code, message, status, meta } } with content-type application/json, not application/problem+json. No type/title/ detail/instance members. source: openapi/eventxtra-public-api-openapi.json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on eventx.io and on esaas-api.eventx.io (probed 2026-08-13). - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no Sunset/Deprecation header documented. - id: pagination conforms: true evidence: >- Consistent page-number pagination — page/pageSize/pageEnd query parameters and a { dataList, pagination: { page, pageSize, pageCount, totalCount } } envelope across all six listing operations. source: conventions/eventxtra-conventions.yml - id: idempotency conforms: false evidence: >- No idempotency-key header or parameter anywhere in the OpenAPI or the docs. Only verifyCustomDomain is described as idempotent, and that is a repeatable status refresh rather than a client-supplied replay key. - id: webhooks conforms: true evidence: >- Documented webhook surface with a managed subscription API (createEventWebhook and siblings) and five attendee lifecycle actions. Captured in asyncapi/eventxtra-webhooks.yml. source: https://eventx-hq.gitbook.io/knowledge-base/api-doc/event-webhook - id: asyncapi conforms: false evidence: No AsyncAPI document published for the webhook surface. - id: mcp conforms: true evidence: >- EventX ships an official hosted MCP server for event data, provisioned one-click from the organizer dashboard and advertised as compatible with Claude, ChatGPT, Cursor and OpenCode. No public endpoint or tool manifest is published, so conformance is asserted from the vendor's own product page, not from a tools/list response. source: https://eventx.io/ - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on eventx.io, esaas-api.eventx.io, help.eventx.io and portal.eventx.io on 2026-08-13 — 404 on the first two, HTML application shells on the other two. No agent card. - id: graphql conforms: partial evidence: >- EventX publishes generated GraphQL schema documentation for its EMS API at https://eventxtra.github.io/ems-graphql-doc/ (Query, Mutation, ~1,000 generated type pages). No endpoint URL is published and every candidate host resolved NXDOMAIN, so the schema could not be introspected and no SDL was captured. source: https://github.com/eventxtra/ems-graphql-doc