Tenant separation
Each client has a dedicated operational PostgreSQL database, with token-bound routing and a restricted runtime role.
Security needs evidence as well as settings. ZipDPDP separates client databases, restricts permissions, signs integration messages and records sensitive administrative actions.
Each client has a dedicated operational PostgreSQL database, with token-bound routing and a restricted runtime role.
Role grants protect workflows and exports. Support access requires a named person, reason, expiry and customer approval.
API secrets are hashed; webhook payloads are signed; receipt and backup keys are versioned for rotation.
Encrypted per-client backups can be verified by isolated restore and guarded two-administrator cutover.
Sensitive events are logged in a tamper-evident chain with redacted exports.
Threat, privacy, accessibility, capacity and release gates are tracked before launch.
Production configuration, offsite storage, alerting, external assessment and staging restore evidence must be completed before public launch. No certification or guaranteed compliance is claimed.
Bring your team, systems and evidence into one working view.