Security & Assurance

Corporate Security Overview

v1.0 · Effective September 18, 2026
Version history
Document IDD21
Versionv1.0
Effective dateSeptember 18, 2026
OwnerSecurity
Contactlegal@zinfitech.com
LayerL1

Corporate Security Overview

EXTERNAL --- CLEARED FOR CLIENT DISTRIBUTION

How ZINFI Technologies, Inc. Secures the ZINFI Unified Partner Management (UPM) Platform and the Organization Behind It

Prepared by ZINFI Technologies, Inc.

Created September 18, 2026

Executive Summary

This document describes the controls ZINFI Technologies, Inc. maintains to secure itself, its infrastructure, and the data it processes on behalf of customers. It is distinct from the security features documented on the ZINFI Products site, which describe capabilities a customer configures inside its own deployment. This document answers a different question: what does ZINFI do to secure ZINFI.

  • ZINFI maintains SOC 2 Type II certification. Framework scope, audit period, and the report itself are available through the request workflow in Section 8 (report detail pending final confirmation --- see note in Section 2).
  • Every ZINFI sub-processor is contractually required to hold SOC 2 Type II or ISO 27001 certification, disclosed in the ZINFI List of Sub-Processors.
  • Customer data is logically isolated per deployment at every platform layer, with no cross-customer query path.
  • A named information security function owns policy, incident response, and vendor risk; a cross-functional AI Model Review Board approves every AI model before production use.
  • Security commitments made in this document are matched by specific, dated obligations elsewhere in the ZINFI estate --- the SLA, the Incident Response commitment, and the AI Addendum --- rather than standing alone as narrative.

1. Purpose and Relationship to Other ZINFI Documents

ZINFI publishes security information in two distinct places, for two distinct audiences, and this document is the second of them.

ZINFI Products - Security & GovernanceThis document
Answers"What can I configure inside UPM?""What does ZINFI do to secure itself?"
CoversSSO, session policy, RBAC, field-level encryption, DSAR tooling, AI access controlCertifications, organizational controls, infrastructure security, vendor risk
AudienceAdministrators configuring a deploymentSecurity reviewers, procurement, auditors
Locatedzinfi.com ProductsZINFI Trust Center

A capability described on the Products page --- for example, field-level encryption with customer-managed keys --- is a feature ZINFI built and makes available. This document states what ZINFI itself does with its own infrastructure, its own personnel, and its own vendors, regardless of how any individual customer configures their deployment.

2. Certifications and Audits

2.1 SOC 2 Type II

ZINFI Technologies, Inc. maintains SOC 2 Type II certification, covering the ZINFI Unified Partner Management platform and the organizational controls supporting it.

Pending confirmation for publication: The audit period, the Trust Services Criteria in scope, and the auditing firm are confirmed internally as of this draft but are not yet finalized for public statement in this document. This section will state each explicitly once confirmed. ZINFI does not publish an audit period, criteria scope, or auditor name it has not verified current --- doing so is treated as a certification claim and is held to the same standard as any other factual assertion in this estate.

This is Version 1.0 of this document and ships in draft status pending that confirmation.

2.2 ISO 27001

ZINFI Technologies, Inc. does not currently hold ISO 27001 certification. Every ZINFI sub-processor that processes Customer Data is contractually required to hold SOC 2 Type II, ISO 27001, or an equivalent recognized framework, disclosed per sub-processor in the ZINFI List of Sub-Processors. Sub-processor certification is not equivalent to, and does not substitute for, ZINFI's own certification, and is stated here as a supply-chain control rather than as a claim about ZINFI itself.

For organizations whose procurement standard defaults to ISO 27001, a mapping between ZINFI's SOC 2 Type II control set and ISO/IEC 27001:2022 Annex A control families is available through the request workflow in Section 8, to support completion of ISO-based vendor questionnaires.

2.3 Requesting the Report

The full SOC 2 Type II report is available to prospective and existing customers under a mutual non-disclosure agreement, through the request workflow described in Section 8.

3. Organizational Security

3.1 Security Governance

Information security policy, incident response, and vendor risk management are owned by ZINFI's Information Security and Privacy function, which reports independently of engineering and product management. A cross-functional AI Model Review Board --- spanning Engineering, Security, and Legal --- approves every AI model before production deployment and reviews flagged AI incidents, consistent with the ZINFI AI Addendum to the DPA.

3.2 Personnel

  • Background screening is performed on employees with access to production systems or customer data, consistent with applicable local law.
  • Security awareness training is required at onboarding and on a recurring basis thereafter.
  • Access to production systems and customer data follows the principle of least privilege and is reviewed on a periodic basis.
  • Personnel found to have circumvented data isolation controls or used partner data outside its authorized scope are subject to disciplinary action up to and including termination, as stated in the ZINFI AI and Partner Data Usage Policy.

3.3 Vendor and Sub-Processor Risk

Sub-processors are evaluated before onboarding and reviewed on a recurring basis against ZINFI's security and data protection requirements. Every sub-processor with access to Customer Data is bound by a data processing agreement consistent with ZINFI's own obligations under the DPA, and is required to hold SOC 2 Type II, ISO 27001, or an equivalent framework. The current sub-processor list, including each sub-processor's certification and the categories of data it processes, is published in the ZINFI List of Sub-Processors and is updated in accordance with the change-notice provisions of the DPA.

4. Infrastructure and Data Security

4.1 Data Isolation

Each customer's deployment is logically isolated within ZINFI's platform infrastructure. Partner and customer data belonging to one customer is inaccessible to any other customer's deployment. This isolation is enforced at the data storage layer through dedicated, logically isolated database partitions with cross-customer queries architecturally prevented at the data access layer; at the AI processing layer, where analysis and recommendations are scoped exclusively to the requesting customer's own dataset; and at the API layer, where every endpoint enforces customer-scoped authentication tokens.

4.2 Encryption

Customer data is encrypted in transit using industry-standard transport security and encrypted at rest. Customers requiring field-level encryption with customer-managed keys for specific data categories can configure this within their deployment, as described on the ZINFI Products Security & Governance page.

4.3 Access Control

Administrative access to production infrastructure is restricted to authorized ZINFI personnel and requires multi-factor authentication. Customer-facing access control --- including single sign-on integration, session policy, and role-based permissions within a deployment --- is a configurable platform capability described on the ZINFI Products Security & Governance page.

4.4 Business Continuity and Recovery

ZINFI maintains documented business continuity and disaster recovery procedures, including defined recovery objectives for the production platform. Availability commitments to customers, including scheduled maintenance and the measurement methodology, are stated in the ZINFI Service Level Agreement.

4.5 Penetration Testing

ZINFI commissions independent third-party penetration testing of the production platform on a recurring basis. Findings are tracked to remediation following the same severity-based targets ZINFI applies to vulnerabilities reported under the ZINFI Vulnerability Disclosure Policy. A summary of testing cadence and scope is available through the request workflow in Section 8.

5. AI Security and Governance

AI Features within the platform are governed by the controls described in the ZINFI AI and Partner Data Usage Policy and given contractual effect in the ZINFI AI Addendum to the DPA, including a categorical prohibition on training any AI model with customer data, deployment-scoped processing isolation, mandatory output labeling, and human review before any externally-impactful AI output is delivered. This document incorporates those commitments by reference rather than restating them, so that a single change to AI governance is reflected in one place.

6. Incident Response

ZINFI's detection, containment, and customer notification commitments for security incidents --- including the seventy-two hour breach notification window and the thirty-day post-incident report --- are stated in full in ZINFI Incident Response and Breach Notification. That document is the authoritative statement of these commitments; this section exists to confirm that incident response is a standing organizational capability, not an ad hoc response.

7. Compliance Alignment

ZINFI's security and data handling practices are designed to support customer compliance with GDPR, CCPA, and comparable data protection frameworks, as detailed in the ZINFI GDPR Compliance and CCPA Compliance pages and the Data Processing Addendum. This document does not itself constitute a compliance certification; it describes the controls that support the commitments made in those documents.

8. Requesting Further Information

The following are available to prospective and existing customers through the ZINFI Trust Center request workflow, typically under a mutual non-disclosure agreement for material marked confidential:

  • The current SOC 2 Type II report.
  • The SOC 2 to ISO/IEC 27001:2022 Annex A control mapping.
  • A summary of penetration testing scope and cadence.
  • Completion of a customer-provided security questionnaire.

Requests are logged and acknowledged within the response targets stated in the ZINFI Service Level Agreement for general support requests.

Document version: This is Version 1.0 of the ZINFI Corporate Security Overview, effective September 18, 2026, published in draft status pending confirmation of the audit-period detail in Section 2.1. Owner: ZINFI Technologies Information Security and Privacy Office. Next scheduled review: September 2027, or immediately upon confirmation of the pending detail, whichever is sooner.

Closing Summary

ZINFI maintains SOC 2 Type II certification and requires every sub-processor to hold SOC 2 Type II, ISO 27001, or an equivalent framework. Customer data is logically isolated per deployment at the storage, AI processing, and API layers. A named security function governs policy, vendor risk, and AI model approval, and the specific commitments referenced here --- availability, incident notification, and AI governance --- are each stated in full in their own dedicated documents rather than restated inconsistently across the estate.

  1. Request the SOC 2 Type II report or the ISO 27001 mapping through the Trust Center if needed for your own vendor risk review.
  1. Review the ZINFI List of Sub-Processors for the certification and data categories applicable to your deployment.
  1. Cross-reference the ZINFI Service Level Agreement and Incident Response and Breach Notification documents for the specific, dated commitments underlying the controls described here.
  1. Contact ZINFI through the Trust Center with any security questionnaire or additional evidence request.

legal@zinfitech.com | zinfi.com/trust-compliance-center

EXTERNAL --- CLEARED FOR CLIENT DISTRIBUTION

Related documents

Contact

Questions about any document on this register: legal@zinfitech.com

6200 Stoneridge Mall Road, Suite 300, Pleasanton, CA 94588