Home/Security

Security & data handling

Your list is not our product.

A file sent for validation is usually your client’s contact database, not your own. Here is exactly what happens to it, what never does, and where we are on certification.

Controls

What we do with your data.

Retention

Deleted when the campaign is removed

Submitted data is used only for validation. It is never added to our own database, never used to enrich another customer’s file, and never sold or shared.

  • Deleted on campaign removal
  • Earlier deletion on written request
  • Never resold, never reused
Isolation

Your own workspace

Every client runs on a dedicated instance with its own configuration and its own rulebook. Client data is not pooled.

  • Dedicated per-client workspace
  • SFTP pull or your own upload
  • No shared processing tenancy
Protection

Encrypted in transit and at rest

TLS 1.2+ in transit and AES-256 at rest. Access is named, least-privilege and logged.

  • Named, least-privilege access
  • Access logged and reviewable
  • Vulnerability scanning on an annual cycle
Access model

No credentials, seats or logins

We never ask for access to your CRM, ESP or any third-party platform. There is nothing to provision and nothing to revoke.

  • Backend-to-backend processing
  • No third-party credentials held
  • Nothing an attacker could take that reaches you
Certification

We would rather tell you where we are than show you a badge.

A badge implies an audit. We have not completed one, so there is no badge on this site.

SOC 2 aligned — our controls are built and documented against the Trust Services Criteria: access control, change management, encryption, monitoring and incident response. We have not yet completed a third-party audit, and we will tell you that before you ask.
GDPR compliant — DPA on request, EU/UK transfers under Standard Contractual Clauses, subprocessor list on request, and data subject requests actioned within 30 days.
Diligence

Send us your questionnaire.

We complete security questionnaires in five business days, because the answer to “can we trust you with this data” should be a document you can file.

Information security policy

Control summary.

The control set we operate against, stated as a policy rather than as reassurance. The binding version is Annex 2 of the Data Processing Agreement; this is the same content in one page.

DocumentInformation Security Policy — control summary
Version1.0
Effective date15 July 2026
Review cycleAnnually, or after any security incident
OwnerData Protection Officer, Zeplinix Technologies Private Limited
FrameworkControls mapped to the SOC 2 Trust Services Criteria. No third-party audit completed
#Control domainOur position
1EncryptionTLS 1.2 or above in transit. AES-256 at rest. Keys held in the hosting provider's key management service.
2Tenancy isolationA dedicated processing workspace per client. No shared processing tenancy. Client data is never pooled.
3Access controlNamed accounts only, least privilege, reviewed quarterly. All access logged and reviewable. No shared credentials.
4AuthenticationMulti-factor authentication required on all administrative access.
5Credential handlingWe hold no credentials to any client system. Files arrive by client-initiated upload or client-provisioned SFTP.
6Change managementPeer-reviewed changes, version control, documented rollback.
7Vulnerability managementAnnual vulnerability scanning, remediation prioritised by severity, dependency monitoring.
8Logging and monitoringAccess and processing logs retained 12 months. Server and security logs retained 90 days.
9Backup and recoveryEncrypted backups. Rotation completes within 35 days. Restoration tested annually.
10PersonnelWritten confidentiality obligations surviving engagement. Data protection training on induction and annually. Access revoked on the last working day.
11Incident responseDocumented procedure. Affected client notified within 24 hours of awareness — inside the 72-hour regulatory window.
12Retention and deletionDeleted on campaign removal and in all cases within 90 days. 30 days after termination. Written confirmation on request.
13SubprocessorsBound by terms no less protective than ours. 30 days notice before any addition, with a right to object.
14CertificationControls documented against SOC 2 Trust Services Criteria. Third-party audit not completed; no SOC 2 report is claimed.

Reporting a vulnerability

If you believe you have found a security issue in anything we operate, email hello@zeplinix.com with the subject line “Security disclosure”. We acknowledge within one business day, keep you informed while we investigate, and will not pursue action against good-faith research that avoids privacy violations, service degradation and data destruction.

Free assessment

Run the assessment on a file you control.

Send 5,000 records, see exactly what comes back, and have the security paperwork in hand before anything larger.

No commitment and no card · hello@zeplinix.com · +91 92700 85057