Account Security
Last updated 11 August 2026
This page explains how signing in to eventru works, where multi-factor authentication (MFA) fits, and what you can do to keep your workspace secure.
Passwordless by design
eventru has no passwords. You sign in with your organisation’s identity provider (Google, Microsoft, or LinkedIn) or with a one-time email link. Because no password exists, there is nothing to phish, reuse, or leak — the attacks MFA is usually deployed against don’t apply here in the first place.
Where multi-factor authentication lives
When you sign in with Google, Microsoft, or LinkedIn, eventru inherits whatever protection your identity provider enforces. If your organisation requires MFA there, every eventru sign-in is covered by it automatically — managed in the place your IT team already manages it.
When you sign in with an email link, your mailbox is the factor: anyone who controls the mailbox controls the sign-in, just like a password reset would on any other product.
- Enforce MFA in your identity provider (Google Workspace, Microsoft Entra) — that is the single most effective step.
- Protect any mailbox that receives sign-in links with MFA too.
- Prefer SSO over email links for team members where you can.
Sessions and devices
Each user can be signed in on at most two devices; signing in on a third signs out the oldest. You can see your active devices — and revoke one, or sign out everywhere — from Settings. Role changes and removals take effect immediately: a removed team member’s existing session loses access on their next request, not when their session expires.
Sensitive actions
Destructive and financial actions (closing a workspace, issuing refunds, exporting or erasing data) require an admin role, an explicit confirmation, and are recorded in your workspace’s audit log.
Reporting a concern
If you believe an account or workspace has been compromised, revoke the affected user’s devices from Settings, remove them from the team if needed, and contact us — we can help investigate using the audit log.