Security
Our Commitment to Security
At ZAAI, security is fundamental to everything we do. We understand that you're entrusting us with sensitive business data, and we take that responsibility seriously.
This page outlines our security practices, certifications, and measures to protect your data.
Infrastructure Security
Cloud Hosting: We run on Google Cloud Platform with data centers in the EU (europe-west1, Belgium).
Network Security: All data in transit is encrypted using TLS 1.3. Internal services communicate over private networks.
Data at Rest: All data is encrypted using AES-256 encryption.
Redundancy: Data is replicated across multiple availability zones for high availability and disaster recovery.
DDoS Protection: Provided by Google Cloud's edge infrastructure.
Application Security
Authentication: Multi-factor authentication (MFA) is available and recommended for all users. Enterprise plans support SSO via SAML 2.0.
Authorization: Role-based access control (RBAC) ensures users only access data they're permitted to see.
Session Management: Sessions expire after inactivity and use secure, httpOnly cookies.
Input Validation: All user inputs are validated and sanitized to prevent injection attacks.
API Security: API endpoints use OAuth 2.0 authentication and rate limiting.
Data Security
Isolation: Each customer's data is logically isolated. Your data is never mixed with other customers' data.
Backups: Automated daily backups with 30-day retention. Backups are encrypted and stored in separate regions.
Data Deletion: When you delete data or terminate your account, data is permanently removed within 90 days.
No Training on Customer Data: We do not use your data to train models for other customers.
Compliance and Certifications
SOC 2 Type II: We maintain a SOC 2 Type II-aligned control framework with regular independent reviews.
GDPR: We are compliant with the General Data Protection Regulation (GDPR) and serve as a data processor.
ISO 27001: We are working toward ISO 27001 certification.
Data Processing Agreements: Available upon request for all customers.
Operational Security
Access Controls: Employee access to production systems is restricted based on role and need.
Background Checks: All employees undergo background checks before accessing sensitive systems.
Training: Security and privacy training is mandatory for all employees.
Device Security: Employee devices must use full-disk encryption and endpoint protection.
Logging and Monitoring: All access and changes are logged. Automated alerts notify our team of suspicious activity.
Vulnerability Management
Regular Scanning: Automated vulnerability scans run weekly. Third-party penetration testing is conducted annually.
Patch Management: Critical security patches are applied within 24 hours. Non-critical patches follow a regular schedule.
Bug Bounty: We operate a responsible disclosure program. Report vulnerabilities to security@zaai.ai.
Dependency Management: Third-party libraries are monitored and updated regularly.
Incident Response
We maintain a documented incident response plan with defined roles and procedures.
In the event of a security incident: We will contain and remediate the issue immediately; Affected customers will be notified within 72 hours; We will provide a post-incident report with root cause analysis.
You can report security concerns to security@zaai.ai. We respond to reports within 24 hours.
Business Continuity
Disaster Recovery: Our RTO (Recovery Time Objective) is 4 hours. Our RPO (Recovery Point Objective) is 1 hour.
High Availability: The Platform is designed for high availability with automatic failover; contractual uptime commitments (99.5% for Professional and Enterprise plans) are defined in the Terms of Service.
Testing: Disaster recovery procedures are tested quarterly.
Enterprise Security Options
For Enterprise customers, we offer:
On-Premise Deployment: Run Horizon in your own data center or private cloud.
VPN Access: Connect to the Platform via dedicated VPN tunnel.
Custom SLAs: Tailored security commitments and response times.
Dedicated Environments: Single-tenant infrastructure for maximum isolation.
Advanced Logging: Export audit logs to your SIEM for centralized monitoring.
Questions and Audits
We're happy to answer security questions and provide documentation.
Enterprise customers may request: documentation of our SOC 2 Type II-aligned control framework; Penetration test results; Security questionnaires; Data processing agreements.
Contact our security team: security@zaai.ai
