Snapshot 21301
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to main content Security How ZenTreasury protects your data. Where customer data lives, how it is isolated, encrypted, backed up and logged, and what your IT reviewer can check without asking us. Contact Sales Founded in Finland. Trusted by finance and treasury teams worldwide Hosted in the EU, one database per customer Production runs in the European Union on established infrastructure providers, behind a network edge that terminates TLS and filters traffic. Each customer has its own database, so isolation is a property of the storage layer rather than a filter in application code. Architecture EU hosting. Production servers and backup storage are in the European Union. A specific server location can be agreed in the Order Form. A separate database per customer. No shared tenant tables and no cross-tenant queries to get wrong. Network edge. Cloudflare terminates TLS, filters traffic and absorbs denial-of-service load in front of every environment. Databases are not internet-facing. Each database is bound to its own host, and servers are reached by key-based SSH only. Encrypted in transit, encrypted backups, tested restores All traffic is served over TLS 1.2 or higher with HSTS enforced, and legacy protocols are refused. Every customer database is backed up nightly, encrypted before it leaves the environment and stored off-site in the EU. Data protection TLS with HSTS. Qualys SSL Labs grades both public endpoints A+ (September 2026). The test is public and can be re-run at any time. Nightly backups per customer. Each customer database is backed up every night to off-site object storage in the EU. AES-256 encrypted archives. Backup archives are encrypted before leaving the environment, with the key held separately from the archives. Restores exercised. Restore procedures have been exercised against production backups and checked against the source. Named users, per-module rights, four-eye approval Every action is authorised on the server. Administrators decide per module who can create, edit or delete, restrict users to specific companies, and route critical treasury transactions through a second approver. Access control Single sign-on. Microsoft Entra ID (Azure AD). Users are provisioned in your tenant first, then sign in with their Microsoft identity. Multi-factor authentication. Available for every user. Organisations on single sign-on enforce it through their identity provider. Per-module permissions. Create, edit and delete rights per module: deals, rates, counterparties, accounts and more. Users can be limited to specific companies. Four-eye approval. Critical treasury transactions require a second approver, and the approval history is retained. Password policy. Minimum length and complexity enforced, each password checked against known-breached lists, stored with bcrypt. Sign-in throttling. Repeated failed sign-ins are rate-limited per account and address. An audit trail your reviewer can open Changes to financial records are recorded with the acting user and time, and the audit trail report is available inside the application. Administrative actions and AI-connector requests are logged separately. Logging Record-level audit trail. Who changed what, and when, per record, in the in-app Audit Trail report. Voucher history. Each accounting voucher keeps its version history, including reversals. Admin audit log. Administrative actions are logged with the acting administrator, the resource and the IP address. AI access logged. The read-only MCP server logs every request. A company admin grants access, and ZenTreasury runs no AI of its own. Central log pipeline. Application, web-server and audit logs ship to a central pipeline with alerting. Verify it yourself Where an independent source exists, we point to it rather than ask you to take our word. Cloud Security Alliance STAR Registry, Level 1 self-assessment ZenTreasury publishes a Consensus Assessments Initiative Questionnaire (CAIQ v4.1) on the public STAR Registry, answered control by control against the Cloud Controls Matrix. View the STAR entry ↗ Qualys SSL Labs Transport security graded A+ Both public endpoints are graded A+: TLS 1.2 and 1.3 only, HSTS enforced, legacy protocols disabled. Re-run the test at any time. Test zentreasury.com ↗ Test zentreasury.eu ↗ International audit firm Independent IFRS 16 review An international audit firm reviewed our IFRS 16 calculations, covering initial recognition, modifications, terminations, foreign currency contracts, interest and depreciation. The full review report is shared during the product walkthrough. Contact Sales Vastuu Group Reliable Partner member ZenTreasury Oy is a member of the Reliable Partner (Luotettava Kumppani®) service, a continuous check on a Finnish company's statutory obligations: taxes and pension contributions paid, statutory insurance and occupational health in place, no business prohibitions. Buyers can pull the report free of charge from Vastuu Group's Reporting Service. About Reliable Partner ↗ Sub-processors A small set of established providers run the service. Each processes customer data only as needed for its function, under a data processing agreement. ProviderPurposeRegion Hetzner Application hosting, databases and backup storage European Union Cloudflare Network edge: TLS termination, traffic filtering, DDoS protection Global edge network Microsoft Azure Backup storage for dedicated environments European Union Freshworks Customer support tickets European Union FAQ Where is our data hosted? In the European Union, on established infrastructure providers, with each customer in its own database. A specific server location can be agreed in the Order Form. Is our data encrypted? All traffic is encrypted in transit over TLS with HSTS enforced. Backups run nightly for every customer database, and the archives are AES-256 encrypted before they are stored off-site in the EU. Does ZenTreasury use AI on our data? No. ZenTreasury runs no AI of its own. If you choose to connect an AI assistant, it reads your data through a read-only MCP server that a company admin enables, and every request is logged. How do we run a security review? Send questionnaires and RFI sections to [email protected]. Our CAIQ on the Cloud Security Alliance STAR Registry answers most standard questionnaires control by control, and we answer the rest directly. What happens to our data when we leave? On request we export your data in a structured, machine-readable format such as CSV. You have at least thirty days to retrieve it, and we then delete what remains, except where the law requires retention. The process is set out in section 13 of our Terms of Service. Procurement or security review? Send questionnaires, RFI sections and architecture questions to [email protected]. We answer directly, and the full CAIQ is public. Contact Sales