Security
Your discovery work stays yours.
Discovery holds the most sensitive version of a project: the problem, the people, and the plan. Here is how ZYRO protects it, in plain language and limited to what the product does today.
01Role-based access
Everyone gets the access their job needs, and no more.
Every member of an organization holds one role: Owner, Admin, Architect, Reviewer, Developer or Viewer. Owners and Admins manage members, settings and billing. Architects run discovery end to end. Reviewers review and approve stages. Developers work with delivery tasks and hand them off. Viewers can read but not change anything.
Each request is checked against the role on the server, not just hidden in the interface.
02Tenant isolation
Your organization's data stays inside your organization.
Data is scoped to the organization and workspace it belongs to, and every read and write is checked against the signed-in member's own organization. Our test suite includes an automated check that looks for queries reaching tenant data without that scope.
03Audit ledger
A record of who did what, that can't be quietly edited.
Organization-level actions such as approvals, role changes, exports and deletion requests are written to an audit ledger. The ledger is append-only: the database refuses to change or delete its rows.
Security events, such as sign-ins, multi-factor changes and revoked sessions, are kept in their own history with the time, IP address and browser involved, so admins can see what happened on their accounts.
04Multi-factor authentication
A second factor on every account that wants one.
Any member can turn on multi-factor authentication with an authenticator app. Members can see their active sessions and sign out of any of them. Passwords are stored only as salted hashes.
05Encrypted secrets
Credentials you give us are encrypted before they're stored.
Integration credentials and other customer secrets are encrypted with AES-256-GCM before they reach the database. API keys you create for ZYRO are stored as hashes, so even we can't read them back.
06Export and deletion
Your data comes with you, and leaves when you ask.
Admins can export an organization's or a workspace's data at any time. Each export is recorded in the audit ledger, and its download stays available for 14 days.
Admins can also request deletion of an organization or workspace. The request is scheduled seven days ahead, so a mistake can be cancelled, and a legal hold can pause it when one applies.
Security questions?
Ask us anything about how ZYRO handles your data. Our Privacy Policy has the details.