Security at Aone
Aone powers high-profile government, enterprise, and public events. Security is engineered into the platform, our infrastructure, and our onsite operations.
1. Infrastructure and hosting
The platform runs on secure, redundant infrastructure hosted inside the Kingdom of Saudi Arabia, delivering 99.99% onsite uptime across flagship events. Environments are isolated, and production access is restricted and logged.
2. Data protection
Data is encrypted in transit (TLS 1.2+) and at rest. Encryption keys are managed centrally with strict rotation and access policies, and backups are encrypted and tested regularly.
3. Access control
Access follows the principle of least privilege.
- Role-based permissions across organizer, operator, and admin accounts.
- Multi-Factor Authentication for platform and admin access.
- Zone- and category-based access segmentation for onsite credentials.
- Full audit logs of administrative and access-control actions.
4. Compliance
Aone is aligned with the Saudi Personal Data Protection Law (PDPL) and applicable National Cybersecurity Authority requirements. Compliance audit tools give organizers a complete record of who accessed what, and when — essential for government and enterprise events.
5. Monitoring and incident response
Systems are monitored continuously for availability and anomalous behavior. A documented incident-response process covers detection, containment, notification to affected organizers, and post-incident review.
6. Onsite operational resilience
Event-day operations are designed to degrade gracefully: gate scanning and badge validation keep working through connectivity interruptions and re-sync automatically, so entry never stops.