Security is our top priority

Security is one of the most important criteria for selecting a deal flow tool. Due to the sensitive nature of the information stored on our platform, your security is of paramount importance. Thanks to our comprehensive security features, we are currently trusted by several big banks, sovereign funds and Fortune 500 companies.

 

security-is-our-priority

Trusted by global leaders in investment
tesi_logo
shv-logo
hilti_2x
capman
mitsubishi-chemical
logo_juuri-partners
Innovestor-dark
haleon-logo-black-1
KIILTO_MASTER_LOGO_BLUE
CCRM-LOGO
veg-capital
logo_kubota
finindus-logo
aliaxis
ub_logo-rgb 1
vv_horizontal
eqbank
sparkmind.vs
synergy_logo
credopartners
andritz_logo_icon
footprint_coalition
anicut
abacus_alpha_logo
thuja_healthcare_investors
knight_logo
alj_logo
industrya

Our application design covers security at multiple layers

ISO/IEC 27001

We have successfully implemented Information Security Management System (ISMS). The ISMS covers all of Zapflow’s systems, services and personnel. Zapflow is recognized and certified as an ISMS compliant, certificate issued on October 20, 2020.

Data security

All data in Zapflow is encrypted at all times when stored, including all database entries, attached documents and emails. The data is stored encrypted in the Amazon Web Services (AWS) RDS service. All documents and email attachments are stored in AWS S3 in encrypted buckets. The encryption keys are managed by AWS KMS. All customer files are scanned for viruses within the AWS S3 with the AWS Lambda antivirus feature. AWS provides services that comply with the highest security standards in the industry, including SOC 3, HIPAA/HITECH, GDPR, PCI DSS Level 1 and MTCS Level 3.

Network security

Any network traffic in and out of our servers will always be transported over encrypted network protocols: SSL, WSS and SSH. The application servers are hosted in a Virtual Private Cloud (VPC) and only the internet-facing application servers are exposed through a firewall and load balancers. The databases and application servers are protected by firewalls. The firewalls only allow access to dedicated ports and protocols required by the application architecture.

Privacy and visibility

We pay the utmost attention to your data privacy and visibility. Access privileges to the data are managed and checked on four levels: input data validation, database queries, business logic and upon data serialization. In addition to that, role-based authorization privileges are checked upon every request to our application servers.

Automated audit logs

All requests to our application servers are logged and logs are stored and encrypted on the AWS S3 service. An object-level change timeline is provided for select objects.

Internal data access

We do not have access to our customers' data. Only within a special control, we might be provided temporary access to your data by authorized employees only to satisfy your special requirements or business needs.

Uptime and durability

The AWS RDS Database is configured with a multi-zone hot-swap replica. The automated backups are stored daily and in multiple locations. We use third-party tools to monitor service availability worldwide and our personnel is automatically notified of any outages.

Virtual private network

Our AWS application servers are protected by firewalls and only the internet-facing servers can be accessed via SSL and WSS protocols. Any other access to our servers is limited to VPN. Access to the VPN is given only to our DevOps team and is only allowed with public key authentication.

Two-factor authentication (2FA)

Our AWS access policy requires all users to use Two-factor authentication (2FA) to log in to Zapflow Amazon Web Services accounts. 2FA can also be integrated into customer user accounts when they login to Zapflow. For more details on this subject please contact sales@zapflow.com.

Amtivo Certificate ISO 27001 2022 1

Zapflow is the first software provider for alternative asset investors globally to achieve the prestigious ISO 27001:2022 certification

Highlighting our dedication to advanced information security and data protection. Leveraging cutting-edge technologies and expertise, we employ comprehensive security measures, including system hardening, encryption (at rest and in transit), multi-factor authentication (MFA), single sign-on (SSO), threat intelligence and analysis, data leakage prevention, incident response and recovery, anti-malware and anti-phishing solutions, as well as ongoing team awareness and education programs. 

Already since 2020, we have successfully implemented and maintained an ISO 27001-certified Information Security Management System. In addition, Zapflow is fully compliant with GDPR, SOC 2, and DORA, seamlessly integrating these regulations and standards into our business processes. 


 

Learn more about our security

The industry leading secure front-office solution for investment professionals

 

whitepaper-book

Ready to steramline your
investment workflows?