Skip to content
Security & Compliance

Your data is safe with us

Zinevu is built on a foundation of security-first engineering, European data residency, and regulatory compliance — so you can focus on your business, not ours.

Data residency
EU only
Uptime SLA
99.9%
Encryption
AES-256
Security practices

Built secure from the start

Security is not a feature we added — it's how the product was designed. Every layer of Zinevu is built with protection in mind.

  • Data encryption

    All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Backups are encrypted independently from the primary store.

  • Access control

    Role-based access control (RBAC) with the principle of least privilege. MFA is available for all accounts and mandatory for admin roles.

  • European data residency

    All customer data is stored and processed within EU data centres (AWS eu-west-1, eu-central-1). We do not transfer data outside the EEA.

  • Continuous monitoring

    24/7 infrastructure and application monitoring. Anomaly detection alerts our on-call team instantly. Uptime SLA of 99.9%.

  • Vulnerability management

    Automated dependency scanning on every pull request. Penetration testing conducted annually by an independent firm.

  • Secure development

    Code review required on every change. Static analysis, SAST tooling, and secrets scanning run in CI before any deployment.

Compliance

Regulatory alignment

We track the frameworks that matter to our customers and work toward certification where it adds real assurance.

  • Compliant

    GDPR

    We act as a data processor under Article 28, with a standard Data Processing Agreement available to all customers.

  • In progress

    SOC 2 Type II

    Audit in progress, expected Q4 2026. Controls are already implemented and being evidenced.

  • Planned

    ISO 27001

    Information security management system in place. Certification process begins H1 2027.

  • Compliant

    NIS2 Directive

    Measures aligned with the EU NIS2 cybersecurity directive requirements for SaaS providers.

FAQ

Common questions

  • Where is my data stored?

    All data is stored in Amazon Web Services (AWS) data centres located in Ireland (eu-west-1) and Frankfurt (eu-central-1). No data leaves the European Economic Area.

  • Can I get a Data Processing Agreement (DPA)?

    Yes. Our standard GDPR-compliant DPA is available in your account settings. For enterprise customers with custom requirements, contact [email protected].

  • How do you handle security incidents?

    We follow a documented incident response plan. Customers are notified within 72 hours of any breach affecting their data, in line with GDPR Article 33.

  • Do you support single sign-on (SSO)?

    Yes. SAML 2.0 SSO is available on the Pro and Scale plans. SCIM provisioning is available on Scale.

  • Can I delete my data?

    Yes. Account owners can request full data deletion at any time. Data is purged within 30 days of the request, with confirmation provided by email.

Responsible disclosure

Found a security vulnerability in Zinevu? Please report it responsibly. We take every report seriously and aim to respond within 48 hours.

[email protected]

Please do not disclose vulnerabilities publicly until we've had the opportunity to address them.