Last updated: August 2026
1.Chapter I: Our Security Commitment
Article (1) Overview
Zyntra Digital is committed to protecting the data of accounting firms and their clients managed through the ZynDesk Platform by applying multi-layered security controls at the infrastructure, application, and operational levels.
2.Chapter II: Infrastructure Security
Article (2) Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256, in accordance with the Privacy Policy and the Data Processing Agreement.
Article (3) Data Hosting
Production data is hosted on Render servers in Frankfurt, Germany, with databases and authentication via Google Firebase (EU region eur3), as further detailed in the Sub-processor Schedule of the Data Processing Agreement.
3.Chapter III: Access Management
Article (4) Two-Factor Authentication and Least-Privilege Access
Two-factor authentication (MFA) is enforced on all internal team accounts and production environments. Access to data is granted on a least-privilege basis, with periodic access reviews.
Article (5) User Permissions (RBAC)
The Platform enables the firm account administrator to define precise permissions for each team member (RBAC), preventing unauthorized access within a single account.
4.Chapter IV: Backup and Disaster Recovery
Article (6) Backup
Automated daily backups of all data are performed, with periodic testing of recovery procedures. The Company adopts a Recovery Point Objective (RPO) of no more than 24 hours and a Recovery Time Objective (RTO) for core systems of no more than 8 hours in the event of a catastrophic incident. These two values represent Target Objectives that the Company endeavors to achieve in accordance with available best technical practices, and do not constitute an absolute guarantee; actual recovery time may be affected by the nature and scope of the incident and factors outside the Company's control.
5.Chapter V: Security Incident Response
Article (7) Response Process
The Company maintains a documented security incident response process covering: detection and containment; impact assessment; notification of affected parties; notification of the Data Controller; and post-incident review to prevent recurrence. The notification timeline (72 hours to Users under the Privacy Policy, and 48 hours to the Data Controller under the Data Processing Agreement) commences from the point of confirmation of an actual security incident posing a risk to personal data — not from the receipt of an automated alert or an unverified initial suspicion. Notwithstanding this, the Company undertakes to investigate any alert or suspicion without undue delay and using reasonable technical resources available to it, in a manner that ensures the investigation phase is not used as a means of delaying required notification.
Article (8) Responsible Vulnerability Disclosure
Security researchers are requested to report any discovered vulnerability to security@zyndesk.app prior to public disclosure. The Company undertakes to acknowledge receipt of the report within 3 business days and to address critical vulnerabilities as a priority.
6.Chapter VI: Compliance Roadmap
Article (9) Current Status and Roadmap
The Company is currently assessing its readiness for SOC 2 Type I certification and aligning its internal controls with ISO/IEC 27001. As of this date, the Company holds neither certification. The controls described on this page are provided on the basis of contractual commitments under the Privacy Policy and the Data Processing Agreement, and this section is updated periodically as progress is made.
Any reference to work undertaken toward these two standards, or any other reference appearing on this page, does not constitute an admission or representation that the Company currently holds ISO/IEC 27001 certification, a SOC 2 report, or any equivalent accreditation or license, and no User or third party may rely on any such reference as evidence of such certification. No formal compliance certification or accreditation shall be recognized unless the Company announces it expressly and makes available the official document issued by the accredited certifying body.