Security

Last updated 21 August 2026

The short version

  • Every page in the signed-in app is checked on the server against your account. You can only ever see your own events.
  • Email travels to us over HTTPS. Inbound webhooks from Mailgun are cryptographically verified before anything is stored.
  • Attachments sit in a private bucket and are downloaded only through short-lived signed links, after an ownership check.
  • We do not claim SOC 2, ISO 27001 or similar certifications. This page describes what the product actually does today.

Encrypted transport

The website is served over HTTPS. Sign-in, the dashboard and inbound email webhooks all use encrypted connections. We do not offer an unencrypted version of the app.

Authentication

You sign in with a one-time code emailed to you, or with Google or Microsoft. Sign-in codes are stored hashed, expire after ten minutes, and the endpoints that issue and check them are rate-limited. Sessions are database-backed and expire after 30 days of inactivity.

Event and account isolation

Every query for an event, message, action, contact or attachment is scoped to the signed-in account. An identifier in the URL is never enough on its own — if the row is not yours, it is treated as missing.

Mailgun webhook validation

Incoming email is posted to us by Mailgun. We verify the HMAC signature and reject requests whose timestamp is too old, so a captured webhook cannot be replayed later. Mail sent to an address we do not recognise is acknowledged and discarded.

Protected attachment storage

Attachment files are stored in a private Google Cloud Storage bucket (or a local folder in development). They are never given a public URL. Downloads go through our server, which checks that you own the parent event, then issues a short-lived signed link.

AI processing

Message text is sent to OpenAI to produce a summary, category, deadlines, actions and contacts. Attachment file contents are not sent — only the file name. Under OpenAI's API terms, data submitted through the API is not used to train its models. We do not use your event content to train models either.

Viewing forwarded email

HTML bodies are sanitised on the server and rendered in an isolated frame with scripts disabled. Remote images are stripped, so opening a message cannot run code or tell the sender you opened it.

Deletion controls

You can delete an individual event or your whole account from the app. Deleting an event removes its messages, attachments, actions and contacts, including the stored files. Deleting an account does the same for every event you own. There is no undelete.

Reporting a problem

If you think you have found a security issue, email privacy@in.onehappening.com. Please do not file a public issue with exploit details.

Questions about security? Email privacy@in.onehappening.com.

See also the OneHappening privacy policy.

See also the OneHappening terms of service.