Skip to content
ZiReach
SECURITY & TRUST

Built to earn trust,
not to claim it.

How we protect your business and your customers — including what is done, what is in progress, and what isn't done yet.

EARLY ACCESSIndia DPDP ActDesigned for the Digital Personal Data Protection Act, 2023 and its rules: consent, rights, grievance officer, breach response.
EARLY ACCESSCard data never touches ZiReachPayments run through our payment partners; we never see or store full card numbers.
PLANNEDSSO & SCIMSAML, Google and Microsoft sign-in with automatic provisioning for larger teams.
PLANNEDSOC 2 / ISO 27001We'll pursue independent audits as customers need them. We don't hold these certifications today.
EARLY ACCESSHealth dataBasic clinical notes as a restricted data class. Not offered to US clinics until a HIPAA path exists.

How we protect your data
The short version, in plain words.

Permission before actionConsent, policy, budget and approval checks run before ZI does anything that reaches a customer or changes a record.
Everything is loggedEvery action records what happened, who or what approved it, and the result.
One business, one boundaryEvery workspace is isolated at the database layer; no business can see another's data.
Encrypted in transit and at restTLS for every connection; our database and storage providers encrypt data at rest.
No training on your customersYour customers' data is never used to train shared AI models. Secrets never enter AI prompts.
India data residencyIndian customers' platform data is planned to be hosted in India (Mumbai region).

ZiReach is in early access; these practices are how the platform is being built and are verified with each pilot. Where something is planned rather than done, we say so.

Subprocessors
Who helps us run ZiReach, and where.

We use a small number of providers for hosting, storage, email, AI models, messaging and payments, under data protection contracts. See the categories and regions; customers can request the named list.