<
Zero-Knowledge Architecture

Security & Privacy

Your data never touches our servers. We built ZazimFind on a zero-knowledge architecture from the ground up, so what you search stays yours, always.

How Zero-Knowledge Works on ZazimFind

Your Device
End-to-End
Encryption
ZazimFind 0 Data Stored ✓ Zero Knowledge
Results Only
Your Device
AES-256 Encryption at rest & in transit (TLS 1.3+)
0 bytes User personal data stored on our servers
72 hrs GDPR breach notification commitment
Zero Trust Internal network model — verify everything

Security Program & Controls

We operate a comprehensive Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022 and the SOC 2 Trust Service Criteria. All infrastructure uses AES-256 or higher encryption for data at rest, backed by FIPS 140-3 compliant key management with hardware security modules (HSMs). Databases and backups use rotating keys, and TLS 1.3 protects all data in transit.

Network segmentation isolates systems into discrete zones, complemented by next-generation firewalls and intrusion detection and prevention systems (IDS/IPS). All API calls and user sessions traverse authenticated, encrypted channels. Administrative access requires multi-factor authentication in line with NIST SP 800-63B recommendations. Regular penetration tests and code reviews enforce application security, and continuous monitoring raises alerts on anomalous login or access patterns.

Encryption

AES-256 at rest, TLS 1.3+ in transit, cloud KMS / HSM managed keys with automatic rotation.

FIPS 140-3

Network Isolation

Firewalls, IDS/IPS, VPN-gated admin access, segmented VPCs per environment.

Zero Trust

Identity & Access

MFA required for all accounts, RBAC least-privilege, privileged-account audit trails.

ISO 27001

Endpoint Security

EDR on all servers, antivirus, automated patch management, hardened OS baselines.

SOC 2

SIEM Monitoring

Aggregated logs, anomaly detection, 24 / 7 alerting, real-time threat intelligence feeds.

NIST RMF

Physical Security

Biometric data-centre entry, on-site guards, CCTV surveillance for owned infrastructure.

ISO 27001

Privacy by Design & Zero Knowledge

ZazimFind is engineered from the ground up around zero knowledge. The service performs its function without ever learning what you are searching for or who you are. Our AI product lifecycle incorporates privacy by design, in line with GDPR Article 25. Data minimisation is not a policy — it is architecture. No personal information is transmitted to or stored by our servers.

Any technical data that briefly passes through our systems, such as request routing metadata, is immediately discarded and never persisted. Data Protection Impact Assessments (DPIAs) are conducted before any new model or dataset is deployed, mapping data flows and obligations. User accounts carry minimal permissions by default, and consent or lawful basis is documented for every processing activity.

We apply purpose limitation and storage limitation strictly. Log data is retained for one year for security auditing only. All user-identifiable content is either never collected or deleted on session close.


Incident Response & Monitoring

Our Computer Security Incident Response Team (CSIRT) operates a structured playbook covering detection through to post-incident review. In line with GDPR Article 33, we commit to notifying the applicable supervisory authority within 72 hours of a qualifying breach. US state laws, including those in California, similarly require timely consumer notification. We treat those deadlines as a floor, not a ceiling.


Governance, Compliance & Certifications

Our policies map to international standards and legal frameworks. A dedicated Data Protection Officer ensures alignment with GDPR, UK DPA 2018, CCPA/CPRA, and emerging AI regulations. For EU/UK cross-border transfers we rely on Standard Contractual Clauses (SCCs) or adequacy decisions, ensuring GDPR Articles 44–46 are satisfied.

GDPR
EU data protection regulation — full Article 25 compliance
UK DPA 2018
UK equivalent; SCCs for cross-border transfers
CCPA / CPRA
California consumer privacy rights implemented
ISO/IEC 27001
Annual audit, information security management
ISO/IEC 27701
Privacy extension to ISO 27001
SOC 2 Type II
Annual independent attestation
NIST AI RMF
AI risk management framework alignment
ISO/IEC 42001
AI governance standard participation

Security Controls Appendix

Control Domain Implementation Standard / Framework
Encryption at Rest AES-256, cloud KMS, HSM key storage, automatic key rotation FIPS 140-3, ISO 27001
Encryption in Transit TLS 1.3+ enforced on all endpoints; HSTS preloaded NIST SP 800-52
Authentication MFA mandatory; phishing-resistant FIDO2 for privileged users NIST SP 800-63B
Access Control RBAC least-privilege; quarterly access reviews; just-in-time access ISO 27001 A.9
Network Security Firewall, IDS/IPS, micro-segmentation, VPN for admin CIS Controls v8
Vulnerability Management Automated scanning, monthly pen tests, CVE monitoring, SLA-based patching OWASP, CVE/NVD
Logging & Monitoring SIEM aggregated, anomaly detection, 1-year log retention SOC 2 CC7
Incident Response CSIRT, documented playbook, 72h GDPR notification SLA GDPR Art. 33
Third-Party Audits Annual ISO 27001, SOC 2 Type II; results reviewed by board ISO 27001 A.18
Business Continuity RPO < 4h, RTO < 8h, geographically redundant backups ISO 22301