ALUNA
Security

Your data, and your event's money, protected by design

It's not a marketing promise — it's Aluna's real architecture: granular roles, optional passwordless authentication, isolation between organizations at the level of every single query, and your own Stripe account collecting directly.

🔑 Granular RBAC

Roles separated by function (admin, member, finance, marketing, analyst...) with individual permissions per module — a marketing member can't see Finance just because they have an account.

🛡️ Passkeys and MFA

Log in with a fingerprint or Face ID (WebAuthn) without a password, or with a code from your favorite authenticator app (1Password, Google Authenticator, Microsoft Authenticator) — your choice.

🏢 Real multi-organization isolation

Every endpoint that receives a resource id validates it belongs to the current session's organization before touching it — not just a visual filter, a check on every server call.

💳 Your own Stripe account

Stripe Connect in direct-charge mode (not destination charges) — the money from your tickets and sponsorships goes straight to your account, never to an Aluna account.

📎 Access-controlled files

Every attachment is served by its own endpoint that explicitly validates whoever requests it has the right to see it — never a file URL accidentally open to the public.

🚦 Fail-closed rate limiting

On public routes without a session (like buying a ticket), if the abuse counter can't be read, the action is rejected — never allowed "just in case" when the protection system fails.

Frequently asked questions

About security

Does my ticket money pass through an Aluna account?

No — we use Stripe Connect in direct-charge mode (not destination charges): the money goes straight to your own Stripe account, never to an Aluna account.

Can I use a physical security key or Face ID instead of a password?

Yes, Aluna supports passkeys (WebAuthn) as well as code-based MFA (TOTP) — you can log in with a fingerprint or Face ID, no password to type.

Can a member of my team see another organization's data?

No — isolation between organizations is real at the level of every single query: every endpoint that receives a resource id validates it belongs to the current session's organization before touching it.

Stop chasing information. Start running your event.

Create free account Talk to us
Create free account