Zetu

Security & trust

What we do, described precisely. Nothing we cannot evidence.

Zetu holds the record of who owes your organization money and what they have paid. This page explains how that record is protected — in specific terms, and without claiming certifications we do not hold.

What Zetu does not claim

Zetu holds no security certifications at this time — not SOC 2, not ISO 27001, not PCI DSS — and makes no compliance claim under any specific data-protection regime as a property of the product. Those are audited attestations and formal legal positions; asserting one without holding it is both dishonest and easy to check.

Everything below describes how the system is actually built. If your procurement process requires a certification, tell us early — that is a real constraint and we would rather know at the first conversation than the fifth.

The most valuable thing in this system is not the money. It is the record of what happened to it.

Zetu does not move money, hold funds or perform any regulated financial activity. Payments flow through your existing providers into your own accounts. That architecture is deliberate and it materially changes the risk profile: an incident here cannot drain an account, because there is no account here to drain.

What Zetu does hold is the interpretation — obligations, allocations, balances, standing, arrangements, waivers and the reasoning behind each. That record is what an arrears schedule, an AGM register or a legal escalation is built on, so its integrity and its history matter more than almost anything else in the product.

How it is built

Controls that are actually in the product.

Role-based access

Permissions are scoped by role and by business unit. A collector working one branch's worklist need not see another's book.

Separated authority

Viewing an account, allocating a payment and waiving a charge are distinct permissions. The decisions that change what someone owes are permissioned separately.

Complete audit trail

Every allocation, un-allocation, waiver, write-off, standing override, arrangement and exception is attributed to a person and timestamped.

Change tracking

Obligations are not silently rewritten. Adjustments, reschedules and corrections preserve the original, so a prior period still reconciles to what it said at the time.

Data isolation

Each organization's data is isolated, and business units within an organization are scoped from one another where policy requires it.

Encrypted transport

All traffic between your browser, Zetu and connected providers travels over encrypted transport. Provider credentials are stored separately from operational data.

Retained provider records

The raw transaction from a rail is kept alongside Zetu's interpretation of it, so a disagreement can be settled by looking rather than by arguing.

User activity records

Sessions and significant actions are recorded, so 'who changed this and when' is answerable after the fact rather than reconstructed.

Backups

Data is backed up on a schedule with defined retention. Restore procedures are exercised rather than assumed.

Procurement

The questions a security review actually asks.

Answered here rather than on request, so an evaluation can start without a meeting. Where an answer is not published yet, this page says which — it does not fill the row with something reassuring.
Security and procurement areas with Zetu's published answer for each.
AreaAnswer
HostingWhich cloud provider runs production, and in which regions?Production runs on Amazon Web Services, with production isolated from the development and testing environments. Infrastructure access is restricted to authorized personnel under least-privilege controls, and AWS maintains the physical security and infrastructure redundancy underneath. Which region a given organization's data sits in is a residency decision rather than a fixed answer — see the row below.
Data residencyWhere does customer data live, and can a region be chosen?Data residency options are available: an organization's data can be held in a specific region rather than wherever the platform defaults to. Which regions are on offer depends on the deployment and is confirmed in contracting, so ask before assuming a particular one.
Encryption in transitHow is traffic protected between the browser, Zetu and connected providers?All traffic between your browser, Zetu and connected payment and messaging providers travels over encrypted transport.
Encryption at restHow is stored data encrypted, and who manages the keys?Stored data is encrypted at rest, using the encryption provided by the underlying database and storage services.
Secrets managementHow are provider credentials and API keys stored and rotated?Secrets and credentials are not held in application source code. Provider credentials are managed separately from the application and stored apart from the operational data they authorize.
AuthenticationIs multi-factor authentication available? Is SSO supported?Zetu supports multi-factor authentication. It is available to users and optional rather than enforced across an organization, so if you need it mandatory, single sign-on is the stronger control — SAML and OIDC are both supported, which lets you keep your own identity provider as the source of truth and enforce the policy there.
Session securityHow do sessions expire, and how is access revoked?Sessions are authenticated and carried over TLS, with tokens and cookies handled securely and an expiry on every session. Logging out invalidates the session. Authorization is checked on the server for every protected resource rather than trusted from the client, and privileged or administrative access carries additional controls.
Access controlHow are permissions scoped, and are privileged actions separated?Permissions are scoped by role and by business unit. Viewing an account, allocating a payment and waiving a charge are distinct permissions, so the decisions that change what someone owes are granted separately from the ability to read the book.
Tenant isolationHow is one customer's data separated from another's?Each organization's data is isolated, and business units within an organization are scoped from one another where policy requires it.
Audit loggingWhat is recorded, and for how long?Every allocation, un-allocation, waiver, write-off, standing override, arrangement and exception decision is attributed to a person and timestamped. The raw provider record is retained alongside Zetu's interpretation of it, so a disagreement can be settled by looking rather than by arguing.
BackupsHow often, retained how long, and are restores tested?Backed up daily, with backups retained for 60 days.
Recovery objectivesWhat are the RPO and RTO targets?Backup and recovery procedures exist to restore service and protect customer data after an infrastructure or application failure, and recovery objectives are set according to how critical a system is. No RTO or RPO figure is published here. Where an organization needs one contractually, it is derived from the actual backup architecture and documented in the service agreement — which is a slower answer than a number on a page, and a more reliable one.
Secure developmentDependency scanning, code review, environment separation?Source control, peer code review, dependency management, separated development, testing and production environments, least-privilege access and controlled deployment. Security is considered through design, development and release rather than checked at the end.
Vulnerability handlingHow is a vulnerability reported, and how quickly is it remediated?Vulnerabilities are assessed on severity and potential customer impact, prioritized accordingly, and remediated through the normal release process or an expedited one. Dependencies and infrastructure are reviewed periodically for known vulnerabilities, and a critical finding can trigger accelerated remediation and an emergency deployment. Report one to the address at the foot of this page.
Incident responseHow and when are customers notified of a security incident?There is an incident-management process covering identification, containment, investigation, remediation, recovery and post-incident review. Security incidents involving customer data are escalated, and affected customers are notified where law or contract requires it. Material incidents are followed by root-cause analysis and corrective action.
SubprocessorsWhich third parties process customer data, and how is a change notified?Zetu uses vetted third-party providers for infrastructure and supporting functions — cloud hosting, communications, monitoring, authentication and related operational services. They are selected on their security and privacy posture, and are bound by contractual data-protection obligations where they process personal data. The current subprocessor list is available to customers, and material changes to it are communicated.
Data retention and deletionHow long is data kept, and what happens after termination?Customer data is retained for as long as providing the service requires, and as long as contractual, legal, security, accounting and regulatory obligations require. After termination or a valid deletion request, data is deleted or anonymized under Zetu's retention procedures — subject to any legally required retention period, and to encrypted backups, where it persists until those backups expire on their normal cycle.
Data processing agreementHow does a customer obtain and review a DPA?Zetu will enter into a Data Processing Agreement where it processes personal data on a customer's behalf. It covers processor obligations, confidentiality, security measures, subprocessors, assistance with data-subject rights, breach notification, deletion or return of data, and international transfer mechanisms where those apply. Ask and we will send it.
AvailabilityIs there a status page or an SLA?Zetu is a cloud service with monitoring and operational controls intended to keep it available. Planned maintenance is kept small and communicated where it is material. No uptime percentage is published, because none has been measured over a period long enough to mean anything. Where an enterprise customer needs an availability commitment, it is documented in an SLA.

Auditability

Designed to be checked, including by people who do not trust it.

Financial software earns trust by being interrogable, not by asserting that it is correct. Three properties do most of that work in Zetu:

  • Every total opens

    A figure in a report can be opened into the obligations and settlements that produced it, and each of those into the payment and the rule or person that allocated it.

  • History is preserved, not overwritten

    An obligation that was disputed and then paid still shows that it was disputed. An arrears figure is reconstructible as at a date in the past, after the committee and the managing agent have both changed.

  • Independent sources are compared

    Where a second record exists — a provider record, a bank statement — Zetu compares rather than trusting whichever system spoke last, and surfaces the disagreement as a finding with a value attached.

Questions

Security questions we get asked

Is Zetu SOC 2 certified? ISO 27001? PCI DSS?

No, and this page will not imply otherwise. Zetu holds no security certifications at this time. Those are formal, audited attestations, and claiming or hinting at one you do not hold is both dishonest and trivially checkable. What this page describes instead is how the system is actually built — which is the thing a certification is meant to evidence, and which you are entitled to interrogate directly.

Are you GDPR compliant?

Compliance is a property of a specific processing arrangement between a controller and a processor, not a badge a product carries. What we can discuss concretely is where data is stored, what is retained and for how long, what happens on deletion, and what a data processing agreement between us would say. Ask, and bring your own counsel — that is a better answer than a tick on a marketing page.

Does Zetu hold our money?

No. Zetu does not move money, hold funds or perform any regulated financial activity. Payments flow through your existing providers into your own accounts. Zetu reads what those systems report and maintains the record of what it meant — which materially reduces what an incident here could cost you.

Who inside our organization can see what?

Access is role-based and scoped, so a collector working one branch's worklist need not see another branch's book, and viewing an account is not the same permission as waiving a charge on it. The decisions that change what someone owes — waivers, write-offs, manual allocations, standing overrides — are permissioned separately and always attributed.

How do we report a vulnerability?

Email security@zetu.app with enough detail to reproduce it. We will acknowledge it and tell you what we are doing. Please give us a reasonable opportunity to fix an issue before disclosing it publicly.

Reporting a vulnerability

Email security@zetu.app with enough detail to reproduce the issue. We will acknowledge it and tell you what we are doing about it. Please give us a reasonable opportunity to fix it before disclosing publicly.

Send us your security questionnaire.

Most of it is answered above. Send the rest and we will answer it directly, including where the honest answer is 'not yet'.