Skip to content

Security · Data security

Built secure,not securedafterwards.

How Zyposoft protects data in the software we build and run: encrypted on the way in, secrets sealed, every request checked, the system split so no single part hands over the rest, and every action on record.

Four protections · 1

Encrypted on the way in.

Connections between people and the system are encrypted. Passwords are hashed with a memory-hard algorithm and a random salt, so they can never be read back, only checked.

Four protections · 2

Secrets sealed.

Integration credentials and keys are stored as ciphertext, apart from everyday data. The key comes from the deployment, never the database, and anything altered is refused on read.

Four protections · 3

Every request checked.

Every route names the permission it needs, and each request is cut down to the caller's scope before any business logic sees it. Nobody signs off their own approval.

Four protections · 4

Split into tiers.

Only the front tier can be reached from outside. The application is reachable only from that tier, and the database only from the application. We choose the deployment with you, including on your own infrastructure.

Defence in depth

No single layer is trusted on its own.

If one layer fails, the next one still holds. A break in the network should not hand anybody the data behind it.

  • NetworkEncrypted, one public surface, the database and messaging never exposed
  • ApplicationA permission per route, scoped queries, rate limits, parts that talk by event
  • DataOne record of truth, isolation between sites, a sealed store for secrets
  • OperationsAppend-only audit trail, SHA-256 hash chains, separation of duties, tracing

Settled with you

Some answers belong in a contract, not on a web page.

Where it is hosted, how backups and retention work, which certifications are in scope and who holds which responsibility depend on your deployment. We agree them with you in writing, and go through them with your security team.

Talk to our security team

We will show you exactly how.

Rather than asking you to take it on trust. Bring your own security review, and we will go through how the software is built and operated.

This page describes how we build and operate software. What any particular deployment ends up with, hosting region, retention, certifications in scope and who holds which responsibility, is settled in your contract and your own security review.