Security

Built with document security in mind

Contracts and operational documents contain sensitive information. ZippedScript is designed with SOC 2-aligned controls covering access, encryption, and audit logging at every layer.

Security controls

How we protect your documents and data at every layer of the stack.

Encryption at rest and in transit

All documents and metadata are encrypted at rest using AES-256. Data in transit uses TLS 1.3. Keys are managed through a dedicated key management service with rotation policies.

Role-based access controls

Access to documents is governed by the roles and permissions your team defines. Approvers see only what they need to approve. Admins control what each role can access, create, or edit.

Immutable audit logging

Every document action is logged with a timestamp, user ID, and IP address. Logs are immutable and cannot be deleted or altered by users. Available for export on all plans.

Single sign-on (SSO)

Business plan customers can authenticate through any SAML 2.0 compatible identity provider. Multi-factor authentication is available and enforceable by account admins on all plans.

Isolated data environments

Customer data is logically isolated by account. Documents, templates, and routing configurations from one account are not accessible to any other account in any context.

Regular backups

Document data is backed up daily with point-in-time recovery available. Backups are stored in geographically separate locations from primary data.

Vulnerability management

We conduct regular internal security reviews and work with third-party researchers through a responsible disclosure program. Critical findings are addressed on a priority basis.

Data deletion on request

Account owners can request full data deletion at any time. All documents, templates, user data, and logs are purged within 30 days of a verified deletion request.

Infrastructure and hosting

ZippedScript runs on cloud infrastructure hosted in Canada and the United States. We use managed services from major cloud providers with established physical and logical security controls.

Our infrastructure is designed with SOC 2-aligned controls across the Trust Services Criteria for security, availability, and confidentiality. We do not store document content on shared storage resources.

Data residency

Customer data, including documents and metadata, is stored in Canada by default. Business plan customers can request data residency configuration for their account. Contact us for details.

Subprocessors

We work with a limited set of subprocessors for infrastructure, email delivery, and payment processing. A current list is available on request.

Security questions?

If you have specific security requirements or questions about our practices, reach out directly. We respond to security inquiries quickly.