Home/Security
Your list is not our product.
A file sent for validation is usually your client’s contact database, not your own. Here is exactly what happens to it, what never does, and where we are on certification.
What we do with your data.
Deleted when the campaign is removed
Submitted data is used only for validation. It is never added to our own database, never used to enrich another customer’s file, and never sold or shared.
- Deleted on campaign removal
- Earlier deletion on written request
- Never resold, never reused
Your own workspace
Every client runs on a dedicated instance with its own configuration and its own rulebook. Client data is not pooled.
- Dedicated per-client workspace
- SFTP pull or your own upload
- No shared processing tenancy
Encrypted in transit and at rest
TLS 1.2+ in transit and AES-256 at rest. Access is named, least-privilege and logged.
- Named, least-privilege access
- Access logged and reviewable
- Vulnerability scanning on an annual cycle
No credentials, seats or logins
We never ask for access to your CRM, ESP or any third-party platform. There is nothing to provision and nothing to revoke.
- Backend-to-backend processing
- No third-party credentials held
- Nothing an attacker could take that reaches you
We would rather tell you where we are than show you a badge.
A badge implies an audit. We have not completed one, so there is no badge on this site.
Send us your questionnaire.
We complete security questionnaires in five business days, because the answer to “can we trust you with this data” should be a document you can file.
Control summary.
The control set we operate against, stated as a policy rather than as reassurance. The binding version is Annex 2 of the Data Processing Agreement; this is the same content in one page.
| Document | Information Security Policy — control summary |
|---|---|
| Version | 1.0 |
| Effective date | 15 July 2026 |
| Review cycle | Annually, or after any security incident |
| Owner | Data Protection Officer, Zeplinix Technologies Private Limited |
| Framework | Controls mapped to the SOC 2 Trust Services Criteria. No third-party audit completed |
| # | Control domain | Our position |
|---|---|---|
| 1 | Encryption | TLS 1.2 or above in transit. AES-256 at rest. Keys held in the hosting provider's key management service. |
| 2 | Tenancy isolation | A dedicated processing workspace per client. No shared processing tenancy. Client data is never pooled. |
| 3 | Access control | Named accounts only, least privilege, reviewed quarterly. All access logged and reviewable. No shared credentials. |
| 4 | Authentication | Multi-factor authentication required on all administrative access. |
| 5 | Credential handling | We hold no credentials to any client system. Files arrive by client-initiated upload or client-provisioned SFTP. |
| 6 | Change management | Peer-reviewed changes, version control, documented rollback. |
| 7 | Vulnerability management | Annual vulnerability scanning, remediation prioritised by severity, dependency monitoring. |
| 8 | Logging and monitoring | Access and processing logs retained 12 months. Server and security logs retained 90 days. |
| 9 | Backup and recovery | Encrypted backups. Rotation completes within 35 days. Restoration tested annually. |
| 10 | Personnel | Written confidentiality obligations surviving engagement. Data protection training on induction and annually. Access revoked on the last working day. |
| 11 | Incident response | Documented procedure. Affected client notified within 24 hours of awareness — inside the 72-hour regulatory window. |
| 12 | Retention and deletion | Deleted on campaign removal and in all cases within 90 days. 30 days after termination. Written confirmation on request. |
| 13 | Subprocessors | Bound by terms no less protective than ours. 30 days notice before any addition, with a right to object. |
| 14 | Certification | Controls documented against SOC 2 Trust Services Criteria. Third-party audit not completed; no SOC 2 report is claimed. |
Reporting a vulnerability
If you believe you have found a security issue in anything we operate, email hello@zeplinix.com with the subject line “Security disclosure”. We acknowledge within one business day, keep you informed while we investigate, and will not pursue action against good-faith research that avoids privacy violations, service degradation and data destruction.
Run the assessment on a file you control.
Send 5,000 records, see exactly what comes back, and have the security paperwork in hand before anything larger.
No commitment and no card · hello@zeplinix.com · +91 92700 85057