Third Party Index

Snapshot 53202

Document
Subprocessor list
URL
https://trust.ziwo.io/#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
90385 bytes
SHA-256 (raw)
98ff74d3b1fc7e7fa1ba898fc8a4fdc93e2a6a14b55df88c7d7f07a03d163703
SHA-256 (normalized text)
90f6d0ef9b77390b35823e5900c450f8b0387133942e644261bb3a5b1f62ed9e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

ZIWO is continuously monitoring its overall security posture.
Announcements
ZIWO renews its ISO/IEC 27001:2022 certification
Published on Aug 20, 2026
We've successfully renewed our ISO/IEC 27001:2022 certification with zero major nonconformities and zero minor nonconformities!
This renewal reaffirms our continued commitment to protecting customer data and maintaining a mature, effective information security management system. The official certificate has been uploaded to our Trust Center as well.
You can find our audit documentation and related evidence in our Trust Center.
Questions? Reach our compliance team at security@ziwo.io.
Compliance
Documentation of our compliance against global standards including certifications, attestations, and audit reports.
Security
Policies
We continuously monitor
We employ 24/7 automated monitoring of infrastructure, networks, applications and anomaly detection systems. Real-time alerts, combined with our monitoring tools make sure all activity is logged and audited to ensure compliance with ISO 27001 and regional standards.
Note: If a control is passing all tests, it will be marked as green. If a control has a failed test that was not resolved within the past 3 days, it will be marked yellow.
App Security
Annual Penetration Test
Code Review Process
Employee Disclosure Process
Software Development Lifecycle
Vulnerability Management
Data Security
Daily Database Backups
Encryption at Rest
Security Policy
SSL/TLS Enforced
System Access Control Policy
Infrastructure Security
Cloud Data Storage Restricted
Multiple Availability Zones
Password Policy
Security Patches Automatically Applied
Network Security
Denial of Public SSH
Firewalls
Logging/Monitoring
Unique Accounts Used
Organization Security
Acceptable Use Policy
BCDR Plan
Code of Conduct
Disaster Recovery Plan
Incident Response Plan
Incident Response Team
Security Training
Product Security
Hard-Disk Encryption
Session Lock
Terms of Service
Subprocessors
Google Workspace
Data location: United States
Drata
Data location: United States
AWS
Data location: UAE, India, Europe
Hexnode UEM
Data location: United States
GitHub
Code repository
Data location: United States
Linear
Data location: United States
Topics and common questions
9
Answers to all your FAQs can be found here !
Yes. Security is fundamentally integrated into every stage of our Software Development Lifecycle (SDLC) through a formal Secure Development Lifecycle (SDL) framework. We do not treat security as an afterthought; it is systematically designed, implemented, and validated from initial design through deployment and maintenance. Our approach includes:
Security by Design
Secure Coding Standards & Training
Penetration Testing & Vulnerability Management
Deployment & Maintenance Security
All customer data processed by ZIWO is stored exclusively within secure, enterprise-grade data centers located locally in the [UAE, KSA, Europe, India, Egypt etc.] regions. We do not do cross-border data processing and we do not transfer or replicate customer data outside the specified customer hosted regions unless explicitly requested and authorized by the customer for specific disaster recovery purposes.
We are committed to the highest standards of security and compliance, including:
ISO 27001: Certified Information Security Management System (ISMS).
Regional Regulations: Fully compliant with key Middle Eastern regulations such as UAE's NESA IA Standards, SAMA CSF (KSA), GDPR for EU data processing.
Regular Audits: We undergo independent third-party security audits annually. Certifications and audit reports are available to customers within the trust center.
We employ multiple layers of protection:
Encryption: Data is encrypted at rest (using AES-256) within our databases and storage systems, and in transit (using TLS 1.2+) between all user devices, applications, and our data centers.
Access Controls: Strict role-based access control (RBAC), least privilege principles, and multi-factor authentication (MFA) enforcement ensure only authorized personnel can access data.
Data Segregation: Logical separation techniques ensure your data is isolated from other customers within our multi-tenant architecture.
Masking/Anonymization: Sensitive data fields can be masked in interfaces and recordings as per configuration and compliance needs.
Further security controls and policies can be requested from our Trust center portal for verification.
Access to customer data is strictly limited to:
Customer Personnel: Your authorized administrators and agents via the application.
ZIWO Infrastructure Personnel: A limited subset of our infrastructure and operations staff requires access for legitimate operational purposes (e.g., incident resolution, maintenance). All such access requires justification, manager approval, and is properly logged.
Rigorous Monitoring: All privileged access is continuously monitored and audited. Comprehensive audit logs capturing data access and system changes are retained for security analysis and compliance purposes.
Additional details
This Trust Center provides transparent access to:
Our security practices (encryption, access controls, development lifecycle)
Compliance certifications and audit reports
Data residency commitments (all data stored within the customer region)
Policies for incident response, privacy, and third-party risk
We empower customers with the documentation and assurance needed to meet enterprise security and regulatory requirements.
🔗 For audit inquiries: security@ziwo.io
Privacy details
ZIWO privacy policy can be found at https://www.ziwo.io/privacy/