Overview
Security & SSO
Gatsby is SOC 2 Type II certified with enterprise SSO through Okta, Google SSO, magic link login, and enforceable two-factor authentication across your organization.
SOC 2 Type II Certification
Section titled “SOC 2 Type II Certification”An independent auditor evaluates Gatsby’s security controls annually. Not a self-assessment. Not a point-in-time snapshot. A sustained review that covers five trust principles: security, availability, processing integrity, confidentiality, and privacy.
For most enterprise procurement workflows, SOC 2 Type II is the baseline. Without it, you’re often not in the conversation.
What the Certification Covers
Security
Data protected against unauthorized access through encryption and access controls.
Availability
Redundant infrastructure and disaster recovery for reliable uptime.
Processing Integrity
Guest data, RSVPs, and event information processed accurately.
Confidentiality
Guest lists and private event details protected from unauthorized disclosure.
Privacy
Personal information handled in compliance with privacy laws and policies.
Requesting the Report
Contact Gatsby directly through Slack or email. We provide the report for your security review or compliance documentation under NDA.
Okta SSO
Section titled “Okta SSO”Centralize Gatsby access through your Okta tenant. Users sign in once. Offboarding happens automatically when you remove someone from Okta.
What's Supported
- SP-initiated SSO: Start from the Gatsby login page, authenticate through Okta
- IdP-initiated SSO: Start from your Okta app dashboard, land directly in Gatsby
- Automatic provisioning: Users added in Okta gain Gatsby access
- Automatic deprovisioning: Users removed in Okta lose Gatsby access
Requirements
Before you begin, confirm you have:
- Access to an Okta tenant
- Okta administrator privileges
- Admin access to your Gatsby organization
Setup Steps
-
In Okta, navigate to Applications and click Browse App Catalog.
-
Search for “Gatsby” and click Add Integration.
-
Complete General Settings for your organization.
-
In Gatsby, open Team Settings and find the Okta Configuration section.
-
From Okta’s Sign On tab, copy the Client ID and Client Secret into the corresponding Gatsby fields.
-
For the Issuer URL, click the dropdown in Okta’s top right corner and copy the Authorization Server URL.
-
Click Save to complete configuration.
How Users Sign In
Once configured, users can sign in three ways:
From Okta
Click the Gatsby app tile in your Okta dashboard.
From Gatsby Login Page
Click “Login with Okta” on the standard Gatsby login page.
Direct Okta Login
Navigate directly to gatsby.events/oktaLogin for Okta-only authentication.
Google SSO and Magic Links
Section titled “Google SSO and Magic Links”For teams without enterprise SSO requirements, Gatsby offers Google SSO and passwordless magic link login.
Google SSO
- Click Login with Gmail on the Gatsby login page
- Select your Google account
- Optionally grant email sending permissions during login
- Your Google account handles authentication security
Magic Link
- Click Login with Magic Link on the login page
- Enter your email address
- Check your inbox for a secure login link
- Click to sign in without a password
Standard Login
Username and password authentication at gatsby.events/login.
Can be combined with two-factor authentication for additional security.
Two-Factor Authentication
Section titled “Two-Factor Authentication”Add a second verification step to username/password logins. You can enable 2FA for yourself or require it across your organization.
Set Up 2FA for Your Account
-
Click your initials in the top right corner.
-
Select Settings.
-
Click Configure 2FA.
-
Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password, or similar).
-
Enter the code from your authenticator to verify setup.
Require 2FA for Your Organization
Admins can enforce 2FA for all team members.
-
Navigate to Team Settings.
-
Toggle Require Two Factor Authentication to on.
-
All team members will be prompted to set up 2FA on their next login.
When 2FA Doesn't Apply
Gatsby’s 2FA covers username/password logins only.
- Google logins use Google’s own security (including their 2FA if enabled)
- Okta logins use Okta’s security policies
- Magic link logins verify identity through email access
Common Questions
Section titled “Common Questions” Is Okta your only enterprise SSO option?
Currently, yes. Google SSO is available for teams using Google Workspace. If you have specific SSO requirements, contact us to discuss options.
Does Okta SSO cost extra?
Yes. The Okta integration carries an additional cost. Contact us for pricing details.
Can I require everyone on my team to use Okta?
Once Okta is configured, users can sign in through Okta. Contact us about enforcing Okta-only authentication for your organization.
What happens if I lose access to my authenticator?
Contact Gatsby support. We can help you regain access and reset your 2FA configuration.
Do you have a security questionnaire we can use?
Contact us directly. We provide our SOC 2 report and answer specific questions for your security review process.