Yes, AmarEvents is built with security in mind. Passwords are hashed using PHP bcrypt — plain text is never stored. Sessions use HTTP-only, SameSite-protected cookies. All inputs are validated and sanitized against SQL injection. API keys use hash-based authentication with rate limiting. For more, see the Privacy Policy at https://amarevents.zone.id/privacy-policy.