Technical Security Measures |
Measure | Specific measure description |
Measures to ensure on a permanent basis the confidentiality, integrity, availability and resilience of processing systems and services | - Security Controls and Practices: Zakeke follows extensive administrative, operational, and configuration practices to track and protect information through a comprehensive set of security controls and practices.
- Dedicated Security Team: Zakeke has a dedicated security team that continuously improves development, security operations, and threat-mitigation practices to detect and prevent new security threats.
- Reliability Measures: The company is committed to delivering a stable and secure product at scale. They use best-in-class core technologies and have business continuity, disaster recovery, and data backup programs in place to minimize the impact of disruptions.
- Data Privacy and Protection: Zakeke is committed to protecting data from unauthorized access and ensuring compliance with data privacy obligations worldwide. They invest in GDPR compliance and stringent privacy safeguards.
- Compliance Audits: Zakeke encourages independent third-party penetration tests and certifications against data security. Their cloud service providers also undergo regular SOC1, SOC2, and/or ISO/IEC 27001 audits to verify their practices.
- Network Architecture Security: Zakeke practices a layered approach to security for their networks. They implement controls at each layer of their cloud environments, limit network traffic, and use encryption for connections.
- Access Control: Zakeke has well-defined processes for provisioning user access to systems and services. They use role-based access control and require multi-factor authentication for staff to access their cloud environment.
- Configuration Management: Configuration management tools are utilized to manage configurations and changes to servers, ensuring consistency and security.
- Logging and Monitoring: Zakeke aggregates logs from various sources, applies monitoring rules, and flags suspicious activity. They retain logs for a specified period and use them for incident detection and response.
- Business Continuity and Disaster Recovery: Zakeke has business continuity and disaster recovery programs to plan for and handle disruptions with minimal impact on customers.
- Data Encryption: Customer data is encrypted in transit over public networks and at rest using industry-standard encryption methods.
- Tenant Separation: Zakeke logically separates customer data to ensure one customer’s actions cannot compromise the data or service of other customers.
- Incident Response: Zakeke has a comprehensive approach to handling security incidents, including incident detection, containment, eradication, recovery, and notification to affected parties.
- Security Testing: They conduct internal security reviews, external penetration testing, and vulnerability management to identify and address security vulnerabilities.
- Supplier Risk Management: Zakeke reviews and monitors third-party suppliers to ensure they do not jeopardize customer data. They enforce security requirements in supplier contracts.
- Compliance: Zakeke’s security program is developed and run in compliance with GDPR and other relevant data protection regulations.
- Privacy Program: Zakeke has a comprehensive privacy program to ensure data privacy and support customers in meeting their data privacy obligations.
- Information Security Management System (ISMS): Zakeke operates an Information Security Management System certified against ISO/IEC 27001, with documented security policies approved by management and reviewed at least annually.
- Risk Management: Zakeke maintains a formal risk management process, performing periodic risk assessments and maintaining a risk treatment plan to identify and mitigate threats to processing systems and services.
- Personnel Security: Zakeke performs background screening where legally permitted, binds staff and contractors to confidentiality obligations, and enforces a formal onboarding/offboarding process and disciplinary procedures for security violations.
- Security Awareness Training: Zakeke provides mandatory security and privacy awareness training to personnel at onboarding and on a periodic basis, with additional role-based training for sensitive functions.
- Change Management: Zakeke applies a formal change management process, including peer code review, testing, approvals, and separation between development and production environments, to preserve the integrity of processing systems.
- Secure Development Lifecycle: Zakeke integrates security into its software development lifecycle through secure coding standards, automated code and dependency scanning, and security testing prior to release.
- Endpoint Protection: Zakeke protects corporate endpoints with anti-malware/EDR, disk encryption, and centralized device management.
- Key Management: Zakeke manages cryptographic keys through a dedicated key management service with controlled access and periodic rotation.
- Access Reviews: Zakeke reviews user access rights periodically and revokes access promptly upon role change or termination, following least-privilege and need-to-know principles.
- Asset Management and Data Classification: Zakeke maintains an inventory of information assets and classifies data by sensitivity to drive appropriate handling controls.
- Segregation of Duties: Zakeke segregates duties and access rights to reduce the risk of unauthorized or unintended changes to systems and data.
- Backup Restoration Testing: Zakeke periodically restore-tests backups to verify recoverability, and defines RTO/RPO objectives for its business continuity and disaster recovery programs.
- Independent Certifications: Zakeke itself maintains ISO/IEC 27001 certification and undergoes independent SOC 2 audits, with certificates and reports available under NDA upon request.
|
Measures to ensure the ability to promptly restore the availability and access of personal data in the event of a physical or technical incident | - Business Continuity and Disaster Recovery (BC/DR) Programs: Zakeke has established BC/DR programs, which include plans and processes to handle disruptions. These programs aim to minimize the impact of incidents and ensure the availability of services.
- Redundancy Measures: Zakeke utilizes redundancy capabilities, such as availability zones and regions offered by its cloud service provider, Microsoft Azure. This redundancy helps ensure that a failure in one data center does not affect the availability of products or customer data.
- Testing and Verification: Zakeke conducts testing and verification of redundancy measures to ensure they meet resiliency requirements. This includes regular testing of backup and recovery processes.
- Monitoring and Alerting: Zakeke continuously monitors a wide range of metrics to detect potential issues early. Alerts are configured to notify the team when thresholds are breached, allowing for prompt action.
- Backup Program: Zakeke operates a comprehensive backup program for its internal systems and customer data. They use automated daily backups, with support for point-in-time recovery and encryption.
- Retention of Logs: Zakeke retains logs for a specified period, both in hot backup (30 days) and cold backup (365 days). These logs are crucial for incident detection, investigation, and response.
- Incident Response Framework: Zakeke has a well-defined incident response framework that covers incident detection, containment, eradication, and recovery. This framework ensures a systematic approach to handling incidents and restoring services.
- Communication with Customers: In the event of an incident, Zakeke aims to notify customers without undue delay if their data is involved. This includes providing information about the incident and its potential impacts.
- Post-Incident Review: After resolving incidents, Zakeke conducts post-incident reviews to learn from the incident and improve practices. This includes identifying lessons learned and implementing technical solutions and process improvements.
- External Expert Assistance: Zakeke has access to external experts, such as specialist cybersecurity consultants and forensic experts, to assist with incident investigation and response when required.
- Recovery Objectives (RTO/RPO): Zakeke defines recovery time and recovery point objectives (RTO/RPO) for its critical services and reviews them periodically, ensuring that availability and access to personal data can be restored within predefined targets after an incident.
- Business Impact Analysis: Zakeke performs a business impact analysis to identify critical services and data, determine their tolerable downtime, and prioritize the order of restoration during a disruption.
- ICT Readiness for Business Continuity: In line with its ISO/IEC 27001 certification, Zakeke maintains documented, management-approved business continuity and disaster recovery plans that are reviewed and tested at least annually.
- Geographically Redundant Backups: Zakeke stores backups in a location geographically separated from the primary production environment, so that a physical incident affecting one site does not compromise the ability to restore data.
- Backup Integrity and Protection: Zakeke protects backups against unauthorized modification and deletion, including tamper-resistant/immutable retention where applicable, to preserve recoverability in the event of a ransomware or destructive incident.
- Recovery Roles and Responsibilities: Zakeke defines clear roles, responsibilities and escalation paths for business continuity and disaster recovery, so that recovery activities are coordinated and executed promptly during an incident.
|
Measures to ensure system configuration, including configuration by default | - Configuration Management Tools: Zakeke utilizes configuration management tools in its production environments. These tools help manage configurations and changes to servers, ensuring consistency and security.
- Layered Security Approach: Zakeke practices a layered approach to security for its networks. They implement controls at each layer of their cloud environments, dividing the infrastructure by zones, environments, and services. This approach helps control and secure network traffic.
- Zone Restrictions: Zone restrictions are in place to limit different types of network traffic, including office/staff traffic, customer data traffic, CI/CD (Continuous Integration/Continuous Deployment), and DMZ (Demilitarized Zone) network traffic. These restrictions help prevent unauthorized access.
- Environment Separation: Zakeke separates production and non-production environments to limit connectivity between them. Production data is not replicated outside of production environments, enhancing security.
- Access Control: Access into production networks and services is only possible from within those same networks. Services must be explicitly authorized to communicate with each other through an authentication allowlist. This access control ensures that only authorized connections are allowed.
- Virtual Private Cloud (VPC) Routing: Zakeke controls access to sensitive networks using virtual private cloud (VPC) routing, firewall rules, and software-defined networking. These measures enhance network security.
- Encryption: All connections into sensitive networks are encrypted, providing an additional layer of security for data in transit.
- Role-Based Access Control (RBAC): Zakeke uses RBAC based on predefined user profiles to ensure that staff only have access appropriate to their job roles. This approach helps limit access to sensitive areas of the system.
- Authentication: To access Zakeke’s cloud environment, staff members are required to authenticate via multi-factor authentication (MFA). MFA adds an extra layer of security to user access.
- Configuration Baselines: Zakeke monitors the configuration of its Azure environments against established configuration baselines to ensure compliance with security standards.
- Container Security Scanning: Zakeke deploys most of its services using Docker container images. They integrate a full container security scanning process into their CI/CD pipeline, ensuring that containers deployed into development, staging, or production environments are free from vulnerabilities.
- Dependency Scanning: Zakeke uses a combination of tools to scan for and identify dependencies, including open source libraries. They compare these dependencies to a database of known security vulnerabilities.
- Logging and Monitoring: Zakeke aggregates logs from various sources and applies monitoring rules to identify and flag suspicious activity. This approach helps ensure that any configuration changes or security incidents are detected promptly.
- Secure Default Configuration: Zakeke provisions systems and services with secure-by-default configurations, applying the principle of least functionality — unnecessary services, ports and features are disabled, and default or vendor-supplied credentials are removed or changed before deployment.
- Infrastructure as Code: Zakeke provisions and manages its infrastructure through version-controlled Infrastructure-as-Code, ensuring configurations are consistent, repeatable, peer-reviewed and auditable across environments.
- Configuration Change Control: Changes to system configuration follow a formal change-management process — including review, testing and approval before being applied to production — to prevent unauthorized or insecure changes.
- Configuration Drift Detection: Zakeke continuously detects deviations from approved configuration baselines and remediates non-compliant configurations, maintaining a consistent and secure state over time.
- Secrets Management: Zakeke manages credentials, keys and other secrets through a dedicated secrets-management service (e.g., Azure Key Vault), avoiding hardcoded secrets in code or configuration and enforcing controlled access.
|
Measures to ensure limited data retention | - Data Management Policies: Zakeke has developed clear and well-defined data management policies. These policies establish specific timeframes for retaining different types of data. They serve as guidelines for how long data should be kept and when it should be securely removed.
- User Data Deletion: Zakeke respects individuals’ rights to control their own data. Users with Zakeke accounts have the option to request the deletion of their data. Zakeke actively assists users in promptly and securely deleting their information upon request.
- Data Deletion Procedures: To ensure data is not retained longer than necessary, Zakeke maintains systematic procedures for data deletion. These procedures are designed to align with the established data retention policies, ensuring that data is securely removed when it reaches the end of its designated retention period.
- Automated Data Retention: Zakeke employs automated systems and tools to manage data retention. This automation helps guarantee that data is consistently deleted in accordance with predefined policies. This approach minimizes the risk of unintentional data retention.
- Retention Period Monitoring: Zakeke actively monitors data retention periods to identify any instances where data might be retained beyond what is necessary. This proactive monitoring ensures compliance with data retention policies and helps prevent data from being held longer than required.
- Legal and Regulatory Compliance: Zakeke is committed to complying with all relevant legal and regulatory requirements, especially those related to data privacy and protection. They keep abreast of changes in data retention regulations and adjust their practices accordingly to remain in full compliance.
- Data Encryption: During the retention period, Zakeke takes measures to protect data through encryption. This added layer of security ensures that stored data remains confidential and is shielded from unauthorized access.
- Audit Trails: Zakeke maintains detailed audit trails and logs related to data retention and deletion activities. These records provide transparency into data management practices and serve as evidence of compliance with data retention policies.
- Access Controls: Access to retained data is strictly controlled and limited to authorized personnel only. Stringent authentication and authorization controls are in place to guarantee that data is accessed solely for legitimate purposes.
- Vendor and Partner Compliance: Zakeke extends its data retention and deletion policies to its third-party vendors and partners who handle customer data. These external parties are required to adhere to the same rigorous data management practices, ensuring data security and privacy.
- International Data Transfers: Zakeke employs appropriate mechanisms for international data transfers, such as standard contractual clauses, to ensure compliance with data protection regulations when data is transferred across borders.
- Return or Deletion at End of Service: Upon termination or expiry of the service agreement, Zakeke returns or securely deletes all customer personal data at the customer’s choice, save where retention is required by applicable law.
- Secure Data Disposal: When personal data reaches the end of its retention period or is deleted upon request, Zakeke renders it unrecoverable using secure deletion methods such as cryptographic erasure or secure overwriting. Physical destruction of storage media at end of life is handled by its certified cloud provider in accordance with recognized standards.
- Deletion from Backups: Personal data deleted from production systems is also removed from backups within the defined backup retention cycle, so that deleted data is not retained indefinitely in backup copies.
- Anonymisation: Where data must be retained for statistical, analytical or legal purposes beyond its retention period, Zakeke anonymises it so that it can no longer be attributed to an identified or identifiable person.
|