Security Policy

Last updated: July 2026 · Zackgo Enterprises

Security contact: contact@zackgo.com · WhatsApp: +91 91156 96315 · See also Security Overview

1. Purpose

This Security Policy describes Zackgo's administrative, technical, and physical safeguards for protecting Customer Data processed through Zackgo Reports.

2. Security Governance

  • Security responsibilities assigned to platform engineering leadership.
  • Security practices reviewed periodically and updated for evolving threats.
  • Employees and contractors with data access bound by confidentiality obligations.
  • Access to production systems limited to personnel with legitimate need.

3. Technical Controls

  • TLS encryption for data in transit; AES-256 encryption at rest for database and file storage.
  • Row-Level Security enforcing workspace isolation at database layer.
  • Enterprise-grade authentication with secure session management and expiring tokens.
  • Server-side validation on all API endpoints for auth, company ownership, plan, and role.
  • Environment secrets stored outside source code; no service keys in client bundles.
  • Payment webhook signature verification for Razorpay events.

4. Access Control

  • Role-based access: executive, clerk, internal admin.
  • Principle of least privilege for internal administrative access.
  • Customer credentials must not be shared between individuals.

5. Audit Logging

Authentication events, uploads, and significant workspace actions are logged to support security investigation and customer accountability.

6. Backups & Business Continuity

Automated daily backups with point-in-time recovery. Recovery procedures tested periodically. See Trust Center for business continuity overview.

7. Incident Response

  1. Detection: Monitoring, customer reports, and automated alerts.
  2. Containment: Isolate affected systems; revoke compromised credentials.
  3. Assessment: Determine scope, data impact, and root cause.
  4. Notification: Affected customers notified without undue delay where personal data breach is confirmed, per applicable law.
  5. Remediation: Fix vulnerabilities; document lessons learned.

8. Vendor Management

Zackgo engages vetted subprocessors for cloud infrastructure, application hosting, intelligence processing, and payment services. Partners are selected for security posture and bound by contractual data protection requirements. Specific vendor identities are not disclosed in public documentation; Enterprise customers may request additional documentation under confidentiality.

9. Responsible Disclosure

We welcome good-faith security reports. See Responsible Disclosure guidelines.

10. Customer Responsibilities

  • Maintain strong, unique credentials.
  • Promptly report suspected unauthorised access.
  • Ensure uploaded data is authorised for processing.
  • Configure team access appropriately.

© Zackgo Enterprises. All Rights Reserved.