Skip to content
ZipDPDP
SECURITY

Controls designed for accountable operations.

Security needs evidence as well as settings. ZipDPDP separates client databases, restricts permissions, signs integration messages and records sensitive administrative actions.

CAPABILITIES

From policy to daily work

01

Tenant separation

Each client has a dedicated operational PostgreSQL database, with token-bound routing and a restricted runtime role.

02

Scoped access

Role grants protect workflows and exports. Support access requires a named person, reason, expiry and customer approval.

03

Keys and integrations

API secrets are hashed; webhook payloads are signed; receipt and backup keys are versioned for rotation.

04

Recovery

Encrypted per-client backups can be verified by isolated restore and guarded two-administrator cutover.

05

Audit evidence

Sensitive events are logged in a tamper-evident chain with redacted exports.

06

Operational review

Threat, privacy, accessibility, capacity and release gates are tracked before launch.

Production configuration, offsite storage, alerting, external assessment and staging restore evidence must be completed before public launch. No certification or guaranteed compliance is claimed.

START WITH A CLEARER PLAN

Make the next privacy task visible.

Bring your team, systems and evidence into one working view.

Start a trial