> For the complete documentation index, see [llms.txt](https://eventx-hq.gitbook.io/knowledge-base/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://eventx-hq.gitbook.io/knowledge-base/event-setting/security-and-compliance.md).

# Security & Compliance

Understand EventX security standards, data protection practices, and password policy guidelines.

## Overview

EventX is built with security as a priority. The platform is ISO 27001 certified, SSL encrypted, and PCI controlled. This section covers our security certifications, data protection measures, and password best practices.

## Getting Started

* [EventX Password Policy Guidelines](/knowledge-base/event-setting/security-and-compliance/eventx-password-policy-guidelines.md) — Password requirements, complexity rules, and best practices
* [EventX Data Protection and Security](/knowledge-base/event-setting/security-and-compliance/eventx-data-protection-and-security.md) — ISO 27001, SSL, and PCI compliance

## Common Questions

**Q: Is EventX GDPR compliant?** A: Yes, EventX has complied with the EU's GDPR privacy law since May 25, 2018.

**Q: What security certifications does EventX hold?** A: EventX is ISO 27001 certified and was the first Asia-based event management platform to obtain this certification.

**Q: Can I set custom password policies for my organisation?** A: Organisations on the Enterprise Plan can define their own custom password policy settings.
