Security
Security at Fanzava.
Your participants give you their data. We treat it accordingly.
This page covers how we protect it, the privacy frameworks we comply with, and what to forward to your IT team.
Who can see what.
Two layers: sign-in and isolation.
Sign-in. Email and password, magic link, Google. On Enterprise plans, your participants sign in through your own identity provider. Passwords are stored in a form that can't be reversed, even if a database leaked. Two-factor authentication is available to everyone, and required for hub admins on Enterprise plans.
Compatible with your identity provider
- Okta
- Microsoft Entra ID
- Google Workspace
Your hub. Fanzava runs many organisations' hubs on the same platform, but your hub's participants, scores, leaderboards and settings live in their own space, completely separated from every other hub. No one in another hub can see your data. Within your hub, group leaderboards are visible only to members of that group.
Read more in our docs: Authentication methods · SSO · Multi-factor authentication · Tenant isolation
Where your data lives.
Fanzava runs in regional cells, each a complete stack with its own database, and your hub's participants, predictions, scores, leaderboards and settings live in exactly one of them. The European Union (with its database in Frankfurt) and Australia (Sydney) are live today; a United States region is built and not yet serving hubs. Enterprise hubs choose their region. Every other hub is assigned one at sign-up, based on where it was created.
Everything moving between your participants and Fanzava is encrypted, and everything stored is encrypted, with keys managed by the infrastructure provider in the region your data sits in. Customer-managed encryption keys aren't offered, so if your procurement process needs them, raise it before you sign.
Stripe handles all payments. Fanzava never sees card details.
Read more in our docs: Data residency · Data protection
Compliance you can show your team.
Aligned with the privacy and accessibility frameworks that matter for procurement.
| Framework | Status |
|---|---|
| UK GDPR | Compliant. UK participants covered. |
| GDPR | Compliant. |
| Australian Privacy Act | Compliant, including the Notifiable Data Breaches scheme. |
| WCAG 2.1 | AA conformance target across customer-facing interfaces. |
| PCI DSS | Out of scope: Stripe handles payments. |
Read more in our docs: Compliance posture · DPA & GDPR
Always informed.
What happens in your hub, you see. Admin actions, competition changes, sign-ins and account changes are all recorded in an audit log only you can access. You can export it any time. Enterprise plans can stream events to your existing security monitoring tools.
Security questions or issues go to security@fanzava.com, acknowledged within 24 hours, with progress updates every two days until resolved.
If a breach affects your participants' data, we'll tell you within 72 hours, with the detail you need to notify them yourself.
Read more in our docs: Audit logs · Monitoring, DLP & incident response
Built on infrastructure you trust.
Behind Fanzava are the same providers running banks, governments and the platforms your team uses every day.
Read more in our docs: Compliance posture
For your IT or security team.
Built for the IT review. Detailed documentation, organised by topic.
Read the full security documentationFor procurement:
- Data Processing Agreement. Included in our Terms of Service for paid plans, with Standard Contractual Clauses by default. Separately executable for Enterprise.
- Sub-processor list. Published at fanzava.com/legal/sub-processors with 30 days' notice of changes.
- Security questionnaire. Available on request to Enterprise prospects under NDA.
- Architectural review documentation. Available to Enterprise customers under NDA.
Security disclosures: security@fanzava.com
Everything else: Contact us
Questions security teams ask.
The short answers. Each one is covered in depth in the security documentation.
Where is our hub's data stored?
In one regional cell: the European Union (Frankfurt) or Australia (Sydney) today. Enterprise hubs choose the region, and the first choice locks, so a later move is an assisted migration on a ticket. Two small central indexes route hostnames and payments to the right cell, and neither holds participant personal data.
Can our participants sign in through our identity provider?
Yes, on Enterprise. Single sign-on works over SAML or OIDC, with providers such as Okta, Microsoft Entra ID and Google Workspace. Every hub also offers email and password, magic link and Google sign-in.
How are passwords and second factors handled?
Passwords are hashed with Argon2id and never stored, sent or logged in plain text. Authenticator-app two-factor authentication is available on every account, with backup codes for recovery, and it is required by default for hub admins on Enterprise.
Can another organisation on Fanzava see our data?
No. Every request carries its hub's identity and every query is filtered to that hub, so one hub's participants, scores and settings cannot be read from another. Inside your hub, a group's leaderboard is visible only to that group's members.
How long are audit logs kept?
One year on every paid plan and 90 days on Free. Enterprise keeps two years by default and can configure up to seven. A hub that has been on a paid plan keeps the one-year floor even if it later returns to Free.
Do you handle card details?
No. Stripe processes every payment, so card data never reaches Fanzava and PCI DSS is out of scope for us.
How do we report a vulnerability?
Email security@fanzava.com. Reports are acknowledged within 24 hours, with a status update every 48 hours until the issue is resolved.
What happens if there is a breach?
Affected hub admins are told within 72 hours of a breach being confirmed, with the detail you need to notify your own participants and, where it applies, the ICO or another regulator.
Ready for your security review?
Talk to our enterprise team about SSO configuration, DPAs, data residency and procurement support.
Talk to our enterprise team