Third Party Index

Snapshot 21301

Document
Security page
URL
https://www.zentreasury.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
104764 bytes
SHA-256 (raw)
7197a8db825853c4eccd1064f2a5a64ee0ffd52d83528a4b6348c840a7b61d32
SHA-256 (normalized text)
3044f455f3ab9e09ec31d303563692f75b8e9ca87302d5bf26af9aa594e1137a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
Security
How ZenTreasury protects your data.
Where customer data lives, how it is isolated, encrypted, backed up and logged, and what your IT reviewer can check without asking us.
Contact Sales
Founded in Finland. Trusted by finance and treasury teams worldwide
Hosted in the EU, one database per customer
Production runs in the European Union on established infrastructure providers, behind a network edge that terminates TLS and filters traffic. Each customer has its own database, so isolation is a property of the storage layer rather than a filter in application code.
Architecture
EU hosting.
Production servers and backup storage are in the European Union. A specific server location can be agreed in the Order Form.
A separate database per customer.
No shared tenant tables and no cross-tenant queries to get wrong.
Network edge.
Cloudflare terminates TLS, filters traffic and absorbs denial-of-service load in front of every environment.
Databases are not internet-facing.
Each database is bound to its own host, and servers are reached by key-based SSH only.
Encrypted in transit, encrypted backups, tested restores
All traffic is served over TLS 1.2 or higher with HSTS enforced, and legacy protocols are refused. Every customer database is backed up nightly, encrypted before it leaves the environment and stored off-site in the EU.
Data protection
TLS with HSTS.
Qualys SSL Labs grades both public endpoints A+ (September 2026). The test is public and can be re-run at any time.
Nightly backups per customer.
Each customer database is backed up every night to off-site object storage in the EU.
AES-256 encrypted archives.
Backup archives are encrypted before leaving the environment, with the key held separately from the archives.
Restores exercised.
Restore procedures have been exercised against production backups and checked against the source.
Named users, per-module rights, four-eye approval
Every action is authorised on the server. Administrators decide per module who can create, edit or delete, restrict users to specific companies, and route critical treasury transactions through a second approver.
Access control
Single sign-on.
Microsoft Entra ID (Azure AD). Users are provisioned in your tenant first, then sign in with their Microsoft identity.
Multi-factor authentication.
Available for every user. Organisations on single sign-on enforce it through their identity provider.
Per-module permissions.
Create, edit and delete rights per module: deals, rates, counterparties, accounts and more. Users can be limited to specific companies.
Four-eye approval.
Critical treasury transactions require a second approver, and the approval history is retained.
Password policy.
Minimum length and complexity enforced, each password checked against known-breached lists, stored with bcrypt.
Sign-in throttling.
Repeated failed sign-ins are rate-limited per account and address.
An audit trail your reviewer can open
Changes to financial records are recorded with the acting user and time, and the audit trail report is available inside the application. Administrative actions and AI-connector requests are logged separately.
Logging
Record-level audit trail.
Who changed what, and when, per record, in the in-app Audit Trail report.
Voucher history.
Each accounting voucher keeps its version history, including reversals.
Admin audit log.
Administrative actions are logged with the acting administrator, the resource and the IP address.
AI access logged.
The read-only MCP server logs every request. A company admin grants access, and ZenTreasury runs no AI of its own.
Central log pipeline.
Application, web-server and audit logs ship to a central pipeline with alerting.
Verify it yourself
Where an independent source exists, we point to it rather than ask you to take our word.
Cloud Security Alliance
STAR Registry, Level 1 self-assessment
ZenTreasury publishes a Consensus Assessments Initiative Questionnaire (CAIQ v4.1) on the public STAR Registry, answered control by control against the Cloud Controls Matrix.
View the STAR entry ↗
Qualys SSL Labs
Transport security graded A+
Both public endpoints are graded A+: TLS 1.2 and 1.3 only, HSTS enforced, legacy protocols disabled. Re-run the test at any time.
Test zentreasury.com ↗ Test zentreasury.eu ↗
International audit firm
Independent IFRS 16 review
An international audit firm reviewed our IFRS 16 calculations, covering initial recognition, modifications, terminations, foreign currency contracts, interest and depreciation. The full review report is shared during the product walkthrough.
Contact Sales
Vastuu Group
Reliable Partner member
ZenTreasury Oy is a member of the Reliable Partner (Luotettava Kumppani®) service, a continuous check on a Finnish company's statutory obligations: taxes and pension contributions paid, statutory insurance and occupational health in place, no business prohibitions. Buyers can pull the report free of charge from Vastuu Group's Reporting Service.
About Reliable Partner ↗
Sub-processors
A small set of established providers run the service. Each processes customer data only as needed for its function, under a data processing agreement.
ProviderPurposeRegion
Hetzner
Application hosting, databases and backup storage
European Union
Cloudflare
Network edge: TLS termination, traffic filtering, DDoS protection
Global edge network
Microsoft Azure
Backup storage for dedicated environments
European Union
Freshworks
Customer support tickets
European Union
FAQ
Where is our data hosted?
In the European Union, on established infrastructure providers, with each customer in its own database. A specific server location can be agreed in the Order Form.
Is our data encrypted?
All traffic is encrypted in transit over TLS with HSTS enforced. Backups run nightly for every customer database, and the archives are AES-256 encrypted before they are stored off-site in the EU.
Does ZenTreasury use AI on our data?
No. ZenTreasury runs no AI of its own. If you choose to connect an AI assistant, it reads your data through a read-only MCP server that a company admin enables, and every request is logged.
How do we run a security review?
Send questionnaires and RFI sections to [email protected]. Our CAIQ on the Cloud Security Alliance STAR Registry answers most standard questionnaires control by control, and we answer the rest directly.
What happens to our data when we leave?
On request we export your data in a structured, machine-readable format such as CSV. You have at least thirty days to retrieve it, and we then delete what remains, except where the law requires retention. The process is set out in section 13 of our Terms of Service.
Procurement or security review?
Send questionnaires, RFI sections and architecture questions to [email protected]. We answer directly, and the full CAIQ is public.
Contact Sales