Encryption
AES-256 at rest, TLS 1.3+ in transit, cloud KMS / HSM managed keys with automatic rotation.
FIPS 140-3Your data never touches our servers. We built ZazimFind on a zero-knowledge architecture from the ground up, so what you search stays yours, always.
How Zero-Knowledge Works on ZazimFind
We operate a comprehensive Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022 and the SOC 2 Trust Service Criteria. All infrastructure uses AES-256 or higher encryption for data at rest, backed by FIPS 140-3 compliant key management with hardware security modules (HSMs). Databases and backups use rotating keys, and TLS 1.3 protects all data in transit.
Network segmentation isolates systems into discrete zones, complemented by next-generation firewalls and intrusion detection and prevention systems (IDS/IPS). All API calls and user sessions traverse authenticated, encrypted channels. Administrative access requires multi-factor authentication in line with NIST SP 800-63B recommendations. Regular penetration tests and code reviews enforce application security, and continuous monitoring raises alerts on anomalous login or access patterns.
AES-256 at rest, TLS 1.3+ in transit, cloud KMS / HSM managed keys with automatic rotation.
FIPS 140-3Firewalls, IDS/IPS, VPN-gated admin access, segmented VPCs per environment.
Zero TrustMFA required for all accounts, RBAC least-privilege, privileged-account audit trails.
ISO 27001EDR on all servers, antivirus, automated patch management, hardened OS baselines.
SOC 2Aggregated logs, anomaly detection, 24 / 7 alerting, real-time threat intelligence feeds.
NIST RMFBiometric data-centre entry, on-site guards, CCTV surveillance for owned infrastructure.
ISO 27001ZazimFind is engineered from the ground up around zero knowledge. The service performs its function without ever learning what you are searching for or who you are. Our AI product lifecycle incorporates privacy by design, in line with GDPR Article 25. Data minimisation is not a policy — it is architecture. No personal information is transmitted to or stored by our servers.
Any technical data that briefly passes through our systems, such as request routing metadata, is immediately discarded and never persisted. Data Protection Impact Assessments (DPIAs) are conducted before any new model or dataset is deployed, mapping data flows and obligations. User accounts carry minimal permissions by default, and consent or lawful basis is documented for every processing activity.
We apply purpose limitation and storage limitation strictly. Log data is retained for one year for security auditing only. All user-identifiable content is either never collected or deleted on session close.
Our Computer Security Incident Response Team (CSIRT) operates a structured playbook covering detection through to post-incident review. In line with GDPR Article 33, we commit to notifying the applicable supervisory authority within 72 hours of a qualifying breach. US state laws, including those in California, similarly require timely consumer notification. We treat those deadlines as a floor, not a ceiling.
Our policies map to international standards and legal frameworks. A dedicated Data Protection Officer ensures alignment with GDPR, UK DPA 2018, CCPA/CPRA, and emerging AI regulations. For EU/UK cross-border transfers we rely on Standard Contractual Clauses (SCCs) or adequacy decisions, ensuring GDPR Articles 44–46 are satisfied.
| Control Domain | Implementation | Standard / Framework |
|---|---|---|
| Encryption at Rest | AES-256, cloud KMS, HSM key storage, automatic key rotation | FIPS 140-3, ISO 27001 |
| Encryption in Transit | TLS 1.3+ enforced on all endpoints; HSTS preloaded | NIST SP 800-52 |
| Authentication | MFA mandatory; phishing-resistant FIDO2 for privileged users | NIST SP 800-63B |
| Access Control | RBAC least-privilege; quarterly access reviews; just-in-time access | ISO 27001 A.9 |
| Network Security | Firewall, IDS/IPS, micro-segmentation, VPN for admin | CIS Controls v8 |
| Vulnerability Management | Automated scanning, monthly pen tests, CVE monitoring, SLA-based patching | OWASP, CVE/NVD |
| Logging & Monitoring | SIEM aggregated, anomaly detection, 1-year log retention | SOC 2 CC7 |
| Incident Response | CSIRT, documented playbook, 72h GDPR notification SLA | GDPR Art. 33 |
| Third-Party Audits | Annual ISO 27001, SOC 2 Type II; results reviewed by board | ISO 27001 A.18 |
| Business Continuity | RPO < 4h, RTO < 8h, geographically redundant backups | ISO 22301 |