Security
Built with document security in mind
Contracts and operational documents contain sensitive information. ZippedScript is designed with SOC 2-aligned controls covering access, encryption, and audit logging at every layer.
Security controls
How we protect your documents and data at every layer of the stack.
Encryption at rest and in transit
All documents and metadata are encrypted at rest using AES-256. Data in transit uses TLS 1.3. Keys are managed through a dedicated key management service with rotation policies.
Role-based access controls
Access to documents is governed by the roles and permissions your team defines. Approvers see only what they need to approve. Admins control what each role can access, create, or edit.
Immutable audit logging
Every document action is logged with a timestamp, user ID, and IP address. Logs are immutable and cannot be deleted or altered by users. Available for export on all plans.
Single sign-on (SSO)
Business plan customers can authenticate through any SAML 2.0 compatible identity provider. Multi-factor authentication is available and enforceable by account admins on all plans.
Isolated data environments
Customer data is logically isolated by account. Documents, templates, and routing configurations from one account are not accessible to any other account in any context.
Regular backups
Document data is backed up daily with point-in-time recovery available. Backups are stored in geographically separate locations from primary data.
Vulnerability management
We conduct regular internal security reviews and work with third-party researchers through a responsible disclosure program. Critical findings are addressed on a priority basis.
Data deletion on request
Account owners can request full data deletion at any time. All documents, templates, user data, and logs are purged within 30 days of a verified deletion request.
Infrastructure and hosting
ZippedScript runs on cloud infrastructure hosted in Canada and the United States. We use managed services from major cloud providers with established physical and logical security controls.
Our infrastructure is designed with SOC 2-aligned controls across the Trust Services Criteria for security, availability, and confidentiality. We do not store document content on shared storage resources.
Data residency
Customer data, including documents and metadata, is stored in Canada by default. Business plan customers can request data residency configuration for their account. Contact us for details.
Subprocessors
We work with a limited set of subprocessors for infrastructure, email delivery, and payment processing. A current list is available on request.
Security questions?
If you have specific security requirements or questions about our practices, reach out directly. We respond to security inquiries quickly.