Snapshot 53202
Normalized text
Scripts and page chrome removed; this is what change detection compares.
ZIWO is continuously monitoring its overall security posture. Announcements ZIWO renews its ISO/IEC 27001:2022 certification Published on Aug 20, 2026 We've successfully renewed our ISO/IEC 27001:2022 certification with zero major nonconformities and zero minor nonconformities! This renewal reaffirms our continued commitment to protecting customer data and maintaining a mature, effective information security management system. The official certificate has been uploaded to our Trust Center as well. You can find our audit documentation and related evidence in our Trust Center. Questions? Reach our compliance team at security@ziwo.io. Compliance Documentation of our compliance against global standards including certifications, attestations, and audit reports. Security Policies We continuously monitor We employ 24/7 automated monitoring of infrastructure, networks, applications and anomaly detection systems. Real-time alerts, combined with our monitoring tools make sure all activity is logged and audited to ensure compliance with ISO 27001 and regional standards. Note: If a control is passing all tests, it will be marked as green. If a control has a failed test that was not resolved within the past 3 days, it will be marked yellow. App Security Annual Penetration Test Code Review Process Employee Disclosure Process Software Development Lifecycle Vulnerability Management Data Security Daily Database Backups Encryption at Rest Security Policy SSL/TLS Enforced System Access Control Policy Infrastructure Security Cloud Data Storage Restricted Multiple Availability Zones Password Policy Security Patches Automatically Applied Network Security Denial of Public SSH Firewalls Logging/Monitoring Unique Accounts Used Organization Security Acceptable Use Policy BCDR Plan Code of Conduct Disaster Recovery Plan Incident Response Plan Incident Response Team Security Training Product Security Hard-Disk Encryption Session Lock Terms of Service Subprocessors Google Workspace Data location: United States Drata Data location: United States AWS Data location: UAE, India, Europe Hexnode UEM Data location: United States GitHub Code repository Data location: United States Linear Data location: United States Topics and common questions 9 Answers to all your FAQs can be found here ! Yes. Security is fundamentally integrated into every stage of our Software Development Lifecycle (SDLC) through a formal Secure Development Lifecycle (SDL) framework. We do not treat security as an afterthought; it is systematically designed, implemented, and validated from initial design through deployment and maintenance. Our approach includes: Security by Design Secure Coding Standards & Training Penetration Testing & Vulnerability Management Deployment & Maintenance Security All customer data processed by ZIWO is stored exclusively within secure, enterprise-grade data centers located locally in the [UAE, KSA, Europe, India, Egypt etc.] regions. We do not do cross-border data processing and we do not transfer or replicate customer data outside the specified customer hosted regions unless explicitly requested and authorized by the customer for specific disaster recovery purposes. We are committed to the highest standards of security and compliance, including: ISO 27001: Certified Information Security Management System (ISMS). Regional Regulations: Fully compliant with key Middle Eastern regulations such as UAE's NESA IA Standards, SAMA CSF (KSA), GDPR for EU data processing. Regular Audits: We undergo independent third-party security audits annually. Certifications and audit reports are available to customers within the trust center. We employ multiple layers of protection: Encryption: Data is encrypted at rest (using AES-256) within our databases and storage systems, and in transit (using TLS 1.2+) between all user devices, applications, and our data centers. Access Controls: Strict role-based access control (RBAC), least privilege principles, and multi-factor authentication (MFA) enforcement ensure only authorized personnel can access data. Data Segregation: Logical separation techniques ensure your data is isolated from other customers within our multi-tenant architecture. Masking/Anonymization: Sensitive data fields can be masked in interfaces and recordings as per configuration and compliance needs. Further security controls and policies can be requested from our Trust center portal for verification. Access to customer data is strictly limited to: Customer Personnel: Your authorized administrators and agents via the application. ZIWO Infrastructure Personnel: A limited subset of our infrastructure and operations staff requires access for legitimate operational purposes (e.g., incident resolution, maintenance). All such access requires justification, manager approval, and is properly logged. Rigorous Monitoring: All privileged access is continuously monitored and audited. Comprehensive audit logs capturing data access and system changes are retained for security analysis and compliance purposes. Additional details This Trust Center provides transparent access to: Our security practices (encryption, access controls, development lifecycle) Compliance certifications and audit reports Data residency commitments (all data stored within the customer region) Policies for incident response, privacy, and third-party risk We empower customers with the documentation and assurance needed to meet enterprise security and regulatory requirements. 🔗 For audit inquiries: security@ziwo.io Privacy details ZIWO privacy policy can be found at https://www.ziwo.io/privacy/