Ziflow’s hub for accountability, transparency, and security
Our online Trust Center is your 24/7 repository for compliance reports, monitoring details, and other security documentation.
Whatever the size or location, your agency, marketing, or in-house creative team can rest assured that their work is always safe and compliant.
Our online Trust Center is your 24/7 repository for compliance reports, monitoring details, and other security documentation.
From day one, your data remains secure at all times, thanks to Ziflow's integrated privacy and protection features.
Security, availability, and confidentiality trust services criteria
Data protection and subject rights for EU residents
Easily authenticate and manage users at scale
International gold standard for information security management
Maintain creativity and access support as needed
Consistent, trustworthy audit trails for every project
Ziflow partners with globally recognized providers to ensure your data is secure at every step of your review and approval process.
Amazon Web Services (AWS) employs a robust physical security program with multiple certifications, including SOC 1 and 2. Ziflow is hosted with AWS to deliver built-in security features based on best practices that harden its systems and processes.
Crowdstrike provides a comprehensive and automated malware detection service for user-uploaded files. It helps ensure foreign files uploaded to the service are not infected or contain dangerous file types that match a set blocklist.
Network Intrusion Detection System (NIDS) sensors complement native AWS security services. Together, they provide an extra layer of protection for all production assets and further enhance security, allowing your teams to create confidently.
Give your team the go-ahead to focus on what they do best without second-guessing the process.
Ziflow is hosted across multiple availability zones for redundancy and runs a separate disaster recovery instance.
24/7 performance and availability monitoring helps us stay aware of system health and mitigate unforeseen issues early on.
Uptime matters to us as much as it does to you, which is why we set an internal goal of delivering it 99.99% of the time.
Your data's privacy and security are integral to every project your team tackles. Learn how Ziflow encrypts it to increase reliance and alignment with your industry.
bcrypt, a proven algorithm and a top choice for password storage, constantly works behind the scenes to securely hash and salt your entries.
We encrypt all submitted customer data (and any data processed on their behalf) using AES-256. The AWS Key Management Service (KMS) securely stores the encryption keys, and Ziflow rotates the customer master keys (CMK) annually.
All network communications use TLS v1.2 with at least 128-bit AES encryption. It's authenticated using AES_128_GCM and uses ECDHE_RSA as the key exchange mechanism. See how Qualys scores Ziflow’s current TLS configuration.
Ziflow’s tech wizards maintain a rigorous security regimen to ensure its features and updates are bulletproof.
Throughout the software development life cycle, Ziflow incorporates threat modeling, attack surface analysis, security architecture analysis, and continuous security training for its teams.
OWASP, a nonprofit community established in 2001, provides web app security resources. Ziflow follows OWASP’s top 10 recommendations, conducts tests, and uses code scanning for product security.
Identifying and classifying vulnerabilities according to risk and impact, our engineering team follows Patch & Change Management Policies to remediate them within set targets.
Quarterly independent third-party penetration tests and manual and automated methods bolster our security. Our internal teams audit and test to fortify features and the network against vulnerabilities.
Put an end to the review cycle frustrations. Start a free trial of Ziflow without a credit card, and experience creativity without compromise.