Your data is safe with us
Zinevu is built on a foundation of security-first engineering, European data residency, and regulatory compliance — so you can focus on your business, not ours.
- Data residency
- EU only
- Uptime SLA
- 99.9%
- Encryption
- AES-256
Built secure from the start
Security is not a feature we added — it's how the product was designed. Every layer of Zinevu is built with protection in mind.
Data encryption
All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Backups are encrypted independently from the primary store.
Access control
Role-based access control (RBAC) with the principle of least privilege. MFA is available for all accounts and mandatory for admin roles.
European data residency
All customer data is stored and processed within EU data centres (AWS eu-west-1, eu-central-1). We do not transfer data outside the EEA.
Continuous monitoring
24/7 infrastructure and application monitoring. Anomaly detection alerts our on-call team instantly. Uptime SLA of 99.9%.
Vulnerability management
Automated dependency scanning on every pull request. Penetration testing conducted annually by an independent firm.
Secure development
Code review required on every change. Static analysis, SAST tooling, and secrets scanning run in CI before any deployment.
Regulatory alignment
We track the frameworks that matter to our customers and work toward certification where it adds real assurance.
- Compliant
GDPR
We act as a data processor under Article 28, with a standard Data Processing Agreement available to all customers.
- In progress
SOC 2 Type II
Audit in progress, expected Q4 2026. Controls are already implemented and being evidenced.
- Planned
ISO 27001
Information security management system in place. Certification process begins H1 2027.
- Compliant
NIS2 Directive
Measures aligned with the EU NIS2 cybersecurity directive requirements for SaaS providers.
Common questions
Where is my data stored?
All data is stored in Amazon Web Services (AWS) data centres located in Ireland (eu-west-1) and Frankfurt (eu-central-1). No data leaves the European Economic Area.
Can I get a Data Processing Agreement (DPA)?
Yes. Our standard GDPR-compliant DPA is available in your account settings. For enterprise customers with custom requirements, contact [email protected].
How do you handle security incidents?
We follow a documented incident response plan. Customers are notified within 72 hours of any breach affecting their data, in line with GDPR Article 33.
Do you support single sign-on (SSO)?
Yes. SAML 2.0 SSO is available on the Pro and Scale plans. SCIM provisioning is available on Scale.
Can I delete my data?
Yes. Account owners can request full data deletion at any time. Data is purged within 30 days of the request, with confirmation provided by email.
Responsible disclosure
Found a security vulnerability in Zinevu? Please report it responsibly. We take every report seriously and aim to respond within 48 hours.
[email protected]Please do not disclose vulnerabilities publicly until we've had the opportunity to address them.