Trust & security
TickX runs on encrypted infrastructure, least-privilege access, and controls independently audited against SOC 2 Type II and PCI DSS. This page summarises how we protect your data and your customers' payments.


Independently assessed on a recurring basis. Full reports are available under NDA.
Security, availability and confidentiality controls audited annually against the AICPA Trust Services Criteria, by Insight Assurance.
Card payments are processed through a PCI DSS-validated payment processor. TickX never stores full card numbers, CVV or track data. Cardholder data is tokenised at the point of entry and kept out of our environment.
A summary of the controls in place across the TickX environment.
All data in transit is protected with TLS 1.2+, with HTTPS enforced for every browser connection. Databases and cloud storage are encrypted for sensitive data, endpoint devices require full-disk encryption, and payment card numbers are masked to the first six and last four digits only.
Access is provisioned on a least-privilege basis with no default admin rights. Administrator access is limited to named individuals, and all user access is reviewed regularly.
AWS cloud infrastructure is managed via Infrastructure-as-Code with defined security baselines. Firewall and network configuration are audited regularly, centralised logging is retained for a minimum of twelve months, and critical patches are applied within strict SLAs.
External vulnerability scans run weekly across all infrastructure and applications, complemented by professional penetration testing every six months. Any identified vulnerabilities are remediated within strict SLAs.
All code changes go through SAST, secret scanning, dependency review, AI review and peer review before deployment. Production deployments are restricted to defined hours.
Defined response SLAs are implemented throughout the organisation. Post-incident reviews are conducted for all P1 and P2 events.
All critical systems are horizontally scaling services with high-availability multi-region databases and automatic failover. Infrastructure-as-Code enables rapid redeployment if required.
TickX acts as data processor on behalf of our clients, with a lawful basis documented for all processing. Privacy by design is embedded in the development lifecycle, personal data is restricted in development environments, and a 72-hour ICO breach notification process is in place. Our team handles data subject access or deletion requests within strict SLAs.
All suppliers with system access undergo a risk assessment before onboarding. Access is provisioned on a need-to-know basis with unique accounts, and supplier contracts specify minimum security requirements including obligations for handling personal data.
Quarterly risk assessments are aligned to SOC 2 methodology and scored on a 5×5 likelihood and impact scale. Risks are tracked and treated in Hicomply, with senior management sign-off required before implementation.
Sensitive reports are shared under NDA. Get in touch and our security team will follow up.
SOC 2 Type II report summary
The summary audit report, covering security, availability and confidentiality.
PCI DSS Attestation of Compliance
Confirmation of the validated processor handling card payments.
Penetration test summary
Findings and remediation status from our most recent third-party test.
Subprocessor list
The third parties that process data on our behalf, and what each one handles.
Our security team answers procurement questionnaires, vendor assessments and due-diligence requests directly.