01ProspectBuild pipeline. Find the companies worth selling to and start conversations with the right contacts.02CloseThe CRM that runs itself. Your pipeline stays current and your team spends its time selling.03GrowEverything after the sale. Keep your customers, renew them and grow the accounts.04ScaleShape Zero to how your company sells, and hand more of the work to agents as you grow.
Prospect
Close
Grow
Scale
CustomersChangelogCareersPricing
Log inStart for free
    • Prospect
    • Close
    • Grow
    • Scale
  • Customers
  • Changelog
  • Careers
  • Pricing
Log in

On this page

  1. Data Storage and Protection
  2. Access Control
  3. Security Practices
  4. Data Management
  5. Compliance and Testing
  6. Security Updates and Communication
  7. Commitment to Improvement

Data Security

How your data is stored, who can reach it, and what we do when something goes wrong.

Last updated June 1, 2026

At Zero, we take the security and privacy of your data seriously. We maintain robust security practices to protect your business information. This document outlines our key security measures and commitments.

Data Storage and Protection

Encryption

  • All data is encrypted in transit using TLS 1.2+
  • All data at rest is encrypted using AES-256 encryption
  • Database backups are encrypted before being stored
  • Infrastructure is strictly segregated into staging and production environments

Cloud infrastructure

  • Customer data is stored in the EU by default. The few subprocessors operating outside the EU are listed in our DPA and covered by Standard Contractual Clauses. Content delivery and edge caching use globally distributed infrastructure that may include locations outside the EU. A limited number of sub-processors also process data outside the EU; these are listed in our DPA and covered by Standard Contractual Clauses or an equivalent safeguard.
  • We utilize GCP's built-in security features including VPC networks, firewall rules, and IAM roles
  • Regular security patches and updates are applied to all systems
  • Infrastructure is strictly segregated into staging and production environments

Access Control

Employee access

  • Single Sign-On (SSO) is required for all internal systems
  • Multi-Factor Authentication (MFA) mandatory for all employee accounts
  • Background checks are performed during onboarding, to the extent permitted by law
  • Access rights are reviewed regularly and unneeded access is revoked
  • Departing employees lose access through a documented offboarding process

Device security

  • Mandatory device encryption for all work devices
  • Automatic screen locking enforced on all devices
  • Full disk encryption required for all hard drives
  • Device compliance (encryption, screen lock, updates) is continuously verified by an endpoint agent

Customer data access

  • Customer data is logically separated in our databases
  • Access to customer data is logged and monitored
  • Employees can only access customer data when explicitly granted permission e.g. during customer onboarding or support

Security Practices

Authentication

  • Google SSO integration available for customer accounts
  • Automatic lockout and cooldown period after multiple failed login attempts
  • Session timeouts for inactive users

Monitoring and incident response

  • 24/7 automated system monitoring
  • Security logs are retained and protected against tampering
  • Documented incident response procedures
  • We notify affected customers of security incidents without undue delay, in line with our DPA and Terms of Service

Development security

  • Code changes are reviewed before deployment
  • Strict separation between staging and production environments
  • Regular security testing and vulnerability scanning
  • Dependencies are automatically scanned for known vulnerabilities

Data Management

Data retention

  • Customer data is retained only as long as necessary
  • Customers can request data deletion at any time
  • Automated, encrypted backups with regularly tested restoration

Data processing

  • Clear data processing agreements with all third-party vendors
  • Minimal use of third-party services to reduce exposure
  • Regular vendor security assessments

Compliance and Testing

Security assessments

  • Regular internal security audits
  • Independent third-party penetration testing planned as part of our SOC 2 program
  • Continuous vulnerability scanning

Privacy compliance

  • GDPR-compliant processing, with primary data storage in the EU. Transfers outside the EEA are limited to the sub-processors listed in our DPA and are covered by Standard Contractual Clauses or an adequacy decision.
  • Privacy policy available at zero.inc/privacy
  • Data Processing Agreements available upon request

Security Updates and Communication

Staying informed

  • Security advisories sent to all customers for critical updates
  • Regular security newsletter for customers
  • Transparent incident reporting and status updates

Contact

For security-related questions or to report a security concern, please contact security@zero.inc.

Commitment to Improvement

While we currently maintain these security measures, we are committed to continuously improving our security posture. We regularly review and update our security practices based on:

  • Emerging security threats
  • Customer feedback and requirements
  • Industry best practices
  • Changes in the regulatory landscape

Other legal documents

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • Subscription Terms
Zero site
Log inStart for free

Product

Prospect
Close
Grow
Scale
Docs
Changelog

Company

About
Customers
Careers3
Blog
Design in Zero
Trust Center
Contact
llms.txt

Compare

All comparisons
Zero vs HubSpot
Zero vs Attio
Zero vs Pipedrive
Zero vs Lightfield
Zero vs Monaco
Zero vs Folk
Zero vs Clarify
Zero vs Ahoy

Legal

Terms
Privacy
DPA
Subscription
Security

© 2026 ZeroZeeroo Technologies, Inc.