Skip to content

Legal

Security

Last updated: July 23, 2026

Security is part of how we build Zamyu. As an early-stage company, we prioritize practical protections, clear ownership, and honest communication about what we support today and what we are still maturing. Nothing on this page claims certifications we have not completed.

Our principles

  • Protect customer data with layered controls appropriate to our stage.
  • Design for least privilege and secure defaults.
  • Be transparent about capabilities and limitations.
  • Improve continuously based on risk, customer feedback, and industry practice.

Encryption

We protect data in transit and at rest using industry-standard approaches available in our hosting stack.

  • Encryption in transit (TLS) for web traffic between browsers/apps and Zamyu services.
  • Encryption at rest for stored customer data in our hosting environment where supported by the platform.
  • Secrets and credentials are handled with restricted access and rotation practices as our controls mature.

Data privacy

Privacy commitments are detailed in our Privacy Policy. In summary: we process data to provide the service, we do not sell personal information, and we limit access to people and systems that need it to operate Zamyu.

Backups and recovery

We maintain backups of critical application and customer data through our infrastructure providers and internal procedures. Backup frequency, retention, and restore testing continue to mature with the product. Customers who need written recovery objectives for procurement should contact us for the latest available detail.

Access control

Access to production systems is limited to authorized personnel. Inside customer workspaces, role-based permissions are designed so owners can grant least-privilege access to staff.

  • Internal access uses least privilege and is reviewed as roles change.
  • Workspace permissions are intended to separate day-to-day staff actions from administrative controls.
  • Customers remain responsible for managing user invitations, role assignments, and offboarding in their accounts.

Authentication

Users authenticate to access Zamyu workspaces. We continue strengthening authentication options (including stronger MFA and SSO paths) as enterprise needs grow. Customers should protect credentials and enable the strongest available options for their plan.

Infrastructure

Zamyu runs on established cloud infrastructure. We review core hosting and subprocessors for security and reliability practices appropriate to our stage, and we update customer-facing disclosures as vendors or regions change.

Monitoring and logging

We use monitoring and logging to help detect unusual activity and diagnose incidents. Log retention and alerting improve over time as our security operations mature.

Responsible AI and security

Optional AI features are designed to operate within workspace context and should remain under human oversight for consequential actions. AI-related data use, labeling, and limitations are described on our Responsible AI page. Security reviews of AI features follow the same principles as the rest of the platform: minimize unnecessary data exposure and document material risks.

Compliance roadmap (future goals)

We are building toward formal compliance programs that matter to customers, including SOC 2, ISO 27001, and GDPR readiness. These are goals—not completed certifications. When attestations or certifications are achieved, we will update this page and share evidence through appropriate channels.

Shared responsibility

Security is shared. Customers are responsible for managing user access in their workspace, protecting credentials, configuring integrations thoughtfully, and using the product in line with their own policies and legal obligations.

Incidents

If we become aware of a security incident affecting personal data, we will investigate promptly and notify affected customers and regulators as required by applicable law.

Responsible disclosure

If you believe you have found a security vulnerability, please email hello@zamyu.com with details so we can investigate. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.

Questions

Security or privacy questions: hello@zamyu.com. For product demos and procurement discussions, use Contact Sales. You may also review our Privacy Policy and Responsible AI page.