Legal & Trust

Security at Zoveto

Last updated: April 2026

1. Overview

Zoveto is built for operational reliability, data security, and system integrity. This trust center summarizes how we protect systems, process data, and document legal safeguards in practical terms.

Data residencyPrimary production customer application data for India deployments is hosted in India-only AWS regions. Some metadata, support, analytics, email, payment, or communication workflows may be processed by approved subprocessors as described in our policies.
Transport securityTLS is used for client, API, and service endpoint traffic.
BackupsManaged backup and recovery controls are part of production operations and enterprise order terms.
SOC 2 roadmapSOC 2 readiness is on the roadmap; Zoveto does not claim certification before completion.
Penetration testingExternal penetration testing is in progress; summaries may be shared under NDA when available.
Security contactsecurity@zoveto.com

2. Security controls

  • Infrastructure: production services run on Amazon Web Services (AWS).
  • Data residency: primary production customer application data for India deployments is hosted in India-only AWS regions unless a customer separately contracts for another deployment model. Some metadata and supporting workflows, including analytics, email, payments, and support operations, may be processed by the subprocessors listed on our Subprocessors page.
  • In transit: TLS is used for data exchanged between clients, APIs, and service endpoints.
  • At rest: core data stores use encryption-at-rest controls.
  • Access control: role-based access controls (RBAC) and least-privilege access practices.
  • Audit logs: operational and security events are logged for investigation and reliability.
  • Role discipline: user permissions are designed around operational responsibilities so teams can separate admin, finance, warehouse, sales, and support actions.

3. Data & privacy

  • What we collect: account, usage, billing, and operational business data required to deliver the service.
  • How we use data: service delivery, security, support, billing, and platform reliability.
  • Data ownership: customer data belongs to the customer; Zoveto processes it to provide the contracted service.

4. Subprocessors

  • Amazon Web Services (AWS): cloud infrastructure hosting.
  • Google (Gmail SMTP): transactional and operational email delivery.
  • Google Analytics: website analytics when consent is enabled.
  • Microsoft Clarity: session replay and behavioral diagnostics when analytics consent is enabled.
  • Razorpay: payment processing and billing transactions.

Full details are maintained on the Subprocessors page.

5. Compliance posture

Zoveto is built following industry best practices for SaaS security and data protection, including controls aligned to the DPDP Act 2023 and IT Act obligations, and GDPR-ready processing standards for international customers. SOC 2 readiness is on our compliance roadmap. We do not claim SOC 2 or equivalent certifications unless the audit is officially completed and publicly announced.

Independent penetration testing is in progress as part of the security programme. Findings are triaged by severity, remediated according to risk, and executive summaries may be shared with qualified prospects or customers under NDA when available.

6. Data ownership and export

Customer data remains the customer's data. On eligible plans, customers may request exports of operational data in standard machine-readable formats to support migration, analytics, and continuity requirements.

7. Backup and continuity posture

Zoveto designs production systems with managed cloud infrastructure, environment separation, operational monitoring, backup controls, and recovery planning appropriate to the customer's plan and contracted scope. Backup cadence, retention, restoration responsibilities, and recovery commitments are confirmed during onboarding or enterprise order terms where applicable.

8. Service Level Agreement

Paid production subscriptions may be covered by Zoveto's Service Level Agreement, including uptime commitment, support priorities, response targets, service credit process, monitoring, maintenance terms, and exclusions.

See the full Service Level Agreement (SLA).

9. Legal documents

10. Responsible disclosure

If you identify a potential vulnerability, report it to security@zoveto.com with reproducible details. We review good-faith reports and triage based on severity.

Open WhatsApp with a prefilled message to Zoveto