Trust centre

Security built into every ledger.

How we approach identity, data protection, service resilience, and responsible vulnerability reporting.

Identity and access

Users authenticate through managed identity services. Workspace permissions are role-based, sessions are isolated by account, and administrative functions require an administrator role stored in the account profile.

Data protection

Traffic is encrypted in transit using HTTPS. Production services should apply database security rules that restrict every record to authorised users. Sensitive integration credentials should be handled by server-side middleware and never shared through support messages.

Secure operations

We minimise access, monitor service health, keep dependencies current, and review security-relevant changes. Recovery and retention practices are designed around the sensitivity of financial records.

Your security responsibilities

  • Use a unique password and protect access to your email account.
  • Grant administrator access only to trusted staff.
  • Review customer and invoice data before sharing or exporting.
  • Revoke access promptly when a team member leaves.

Report a vulnerability

Send a clear, confidential report to security@zafeq.com. Do not access other customers’ data, disrupt the service, or publish an unresolved issue.