Security and compliance

We never see the identifier we matched.

Matching runs on hashes, and the graph is ours rather than someone else’s file. Two facts that decide most security reviews.

Compliance

Where we stand today

Four regimes, and what each one actually commits us to.

GDPR · EU & UK

Lawful basis for processing, data-subject rights honoured, and matching that never exposes a raw identifier.

CCPA · California

Consumer rights supported, including the right to know what is held and the right to have it deleted.

DPDP 2023 · India

Compliant with the Digital Personal Data Protection Act, which governs the consumer data behind the Grow side.

SOC 2 Type I

AICPA SOC for Service Organizations. Final report available under NDA on request.

How matching works

Your customer list never leaves your system.

The objection every security review raises, answered in three steps.

01 · You send

sha256(“a••••@example.com”)
→ 9f2b41c7…

You hash the email or phone before it leaves your system. The raw identifier never travels.

02 · We match

9f2b41c7… → person_id

We match hash to hash. We never receive, store or need the original — and we cannot work backwards to it.

03 · You get back

{ role, company, seniority, … }

A resolved profile for the identifier you already held. Nothing about anyone you did not ask about.

You get back a profile. We never got back your customer list.

Provenance

The graph is ours.

Where the data comes from matters as much as how it is handled — a resold file carries someone else’s collection practices with it.

Resolved, not licensed

8+ person and 10+ company sources cross-checked into one record per real person.

Never resold

We do not repackage another provider’s file, so their collection practices are never inherited into yours.

99.1% platform uptime

Reliable infrastructure for production applications and critical workflows.

Controls

What is actually in place.

The controls a security review asks about, stated plainly rather than implied.

  • Encrypted in transit and at rest. HTTPS/TLS on every client-facing and internal API; AWS encryption at rest across S3 and RDS.
  • MFA on every tool. Mandatory across all company systems, with no exceptions, set at onboarding and revoked at offboarding.
  • Least-privilege access. Role-based matrix; production access approved by the CTO; engineering holds read-only; access reviewed on any role change.
  • Network segregation. Client-facing systems separated from internal; database traffic restricted to VPN; SSH by key only, passwords disabled.
  • Continuous monitoring. AWS GuardDuty, Inspector and Security Hub, with CloudWatch and CloudTrail logging and monthly control reviews.
  • Weekly backups, tested. EBS snapshots and database dumps taken weekly, verified weekly, with periodic restoration tests.
  • Reviewed change management. Every code and infrastructure change goes through pull request and CTO approval before it reaches production.
  • Security training before access. Completed within 7 days of joining and before production access is granted, refreshed annually.
Continuity

Recovery targets, in numbers.

Committed objectives rather than a promise to try hard.

SystemRecovery timeRecovery point
AWS application servers5 minutes
AWS database30 minutesUp to 7 days
Client and partner data (S3)4–8 hoursUp to 30 days
Office database12 hoursUp to 7 days
Retention

How long anything is kept.

DataRetention
Client delivery data1 month in AWS S3, then deleted
System logs (CloudWatch, CloudTrail)90 days, then auto-deleted
Incident recordsMinimum 3 years
Breach recordsMinimum 5 years
Incident response

What happens when something goes wrong.

Severity decides the clock. Every incident is logged and retained for audit.

SeverityCoversResponse
P1Full outage, confirmed unauthorised access, data breachImmediate, CTO and CEO notified at once
P2Partial degradation, suspected unauthorised accessNotified within 10 minutes, response within 30
P3Minor or non-production issuesResponse within 2 hours, resolution within 24
Policy library

Twenty-three policies, reviewed annually.

Effective February 2026, owned jointly by the CEO and CTO. Any of these can be shared under NDA as part of a security review.

  • Information Security
  • Access Control
  • Password & Authentication
  • Data Protection
  • Data Retention
  • Encryption
  • Backup
  • Business Continuity & DR
  • Change Management
  • Incident Management
  • Breach Management
  • Vendor Management
  • Insider Threat
  • Acceptable Use
  • Compliance
  • Physical Security
  • Remote Access
  • Network Security
  • Endpoint Security
  • Privacy
  • Data Classification
  • Security Awareness Training
  • Disaster Recovery Plan
Sub-processors

Everyone who touches anything.

Maintained as a formal vendor register, reviewed annually for anything with client-data access. Only one sub-processor handles production data.

Sub-processorPurposeData access
Amazon Web ServicesProduction infrastructure — compute, storage, database, CDN and security monitoringClient and production data
ResendTransactional email deliveryRecipient addresses only
Google WorkspaceCorporate email, documents and calendar. Also provides staff single sign-onInternal only — no production data
SlackInternal communications and security alertingInternal only
AtlassianSource control (Bitbucket) and issue tracking (Jira)Internal only
TailscaleVPN tunnels for access to internal systemsNo data access
UptimeRobotUptime monitoring and public status pageNo data access
Your rights

Anyone can ask what we hold, and have it removed.

You do not need to be a ZipLabs customer. These apply to anyone whose record is in the graph.

  • Access
  • Correction
  • Erasure
  • Restriction
  • Portability
  • Objection to automated decision-making

Email support@ziplabs.ai and we’ll verify your identity before acting on the request. Full detail sits in the privacy policy.

Documentation

Send us your security review.

We do not publish a self-serve document portal. Ask, and the right paperwork comes back from a person who can also answer follow-ups.

  • Security overviewAvailable
  • Data processing agreement (DPA)On request
  • SOC reportOn request
  • Sub-processor listOn request
FAQs

Security questions,
answered

Which regimes does ZipLabs comply with?

GDPR (EU and UK), CCPA (California), DPDP 2023 (India), and AICPA SOC. Matching is hashed and privacy-safe throughout.

Do you resell another provider’s data?

No. We resolve and validate our own graph across 8+ person and 10+ company sources and reconcile them into a single answer. Nothing here is a licensed file from someone else.

Do you ever see the raw email or phone we send?

No. Matching runs on hashes, so the identifier never has to leave your system in the clear, and we cannot reconstruct it from what we hold.

How do I request access to, or deletion of, my data?

Email support@ziplabs.ai. We verify your identity before acting on any request. Full detail is in our privacy policy.

How reliable is the platform?

99.1% platform uptime, with the infrastructure running production applications and critical workflows.

Still have questions?

Bring your security review. We’ll answer it.

Fifteen minutes with someone who can speak to how the graph is built and handled.