Security Center
How we protect customer data across the platform, and what we ask of you.
On this page
Zippix is a business platform for financial advisory firms. Protecting the confidentiality, integrity, and availability of Customer data is central to how we design, build, and operate the Service. This page provides an overview of our security approach. Additional or specific commitments apply only where stated in a signed agreement.
1. Our Approach
Zippix applies security in layers — across identity, access control, application logic, infrastructure, and operations — so that no single control is the only line of defence. Security is a shared responsibility: Zippix secures the platform and its infrastructure, while each Customer controls its own users, permissions, connected services, and lawful use of the Service.
Access to production systems is restricted to authorised personnel on a need-to-use basis and protected by dedicated credentials, separate from ordinary user accounts.
2. Infrastructure Security
The Service runs on established cloud infrastructure providers whose data centres maintain industry-standard physical and environmental protections. Infrastructure-level encryption at rest protects stored data, and provider-managed network controls protect the environments in which the Service operates.
Zippix does not commit to a single hosting country or region unless that commitment is included in a signed agreement.
3. Encryption
- Data in transit between browsers, the application, and external providers is protected with encrypted transport (HTTPS/TLS).
- Data at rest is protected with encryption at the infrastructure level.
- Passwords are protected with industry-standard one-way hashing and are never stored or transmitted in readable form.
4. Identity and Access Control
Zippix provides layered access controls that Customers configure to match their organisation:
- Workspace isolation: every record belongs to a Customer workspace, and access is checked against workspace membership.
- Roles and permissions: module-level permissions control which users can access clients, leads, WhatsApp features, administration, and other functions.
- Reporting hierarchy: visibility can follow the Customer's organisational structure.
- Project and folder permissions: access to projects and file folders can be limited to view, edit, or full control.
- Optional IP restrictions: a Customer may limit a user's access to approved IP addresses.
- Session protections: authentication credentials expire, password-reset links are time-limited and delivered to the account email address, and sessions are invalidated when credentials change.
Customers should apply least privilege, review access regularly, and promptly remove accounts that no longer need the Service.
5. Application Security
The application applies controls designed to prevent unauthorised or malformed requests, including validation of incoming requests, authorisation checks on protected operations, workspace-scoped data access, time-limited links for private file access, and rate limiting on sensitive operations.
6. Monitoring and Incident Response
Zippix maintains logging, metrics, and monitoring to support reliability, detect abnormal activity, and investigate authentication or application failures. Operational records are used for service operation, security, and support — never to sell Customer Data, target advertising, or train artificial-intelligence models.
We review credible security reports, investigate events within our control, take reasonable containment and remediation steps, and communicate with affected Customers where required by applicable law or contract.
7. Integrations and Shared Responsibility
Optional integrations, such as WhatsApp through Meta's Cloud API, connect the Service to platforms operated by third parties. Zippix applies its own permissions and workspace controls to these features, while the third party operates its platform under its own security practices. The Customer controls which accounts are connected, which users may use them, and the content and recipients of communications.
Customers should restrict integration configuration to authorised administrators and reconnect or rotate credentials if compromise is suspected.
8. Data Lifecycle
The Service supports record-level deletion for supported workflows, with associated stored files scheduled for subsequent cleanup. Data is retained and deleted in line with the Privacy Policy, and Customers may request an export or deletion review through support@zippix.in.
9. Customer Security Responsibilities
Customers materially affect the security of their own workspace. Customers should:
- give each user an individual account and prohibit credential sharing;
- use strong, unique passwords and protect account email addresses;
- apply the minimum roles and permissions needed, and review them regularly;
- remove or deactivate access promptly when personnel or responsibilities change;
- obtain required authority before storing identity, financial, or communication data;
- protect exported files after they leave Zippix;
- maintain secure devices, browsers, and networks; and
- notify Zippix promptly of suspected misuse or compromise.
10. Report a Security Concern
Send security concerns to:
Zippix Support Team
ANWIT AI, operating Zippix
B-509, Decora 9Square
Nana Mava Road
Rajkot, Gujarat 360003
India
Email: support@zippix.in
Include a clear description of the suspected problem, the affected feature or area, steps to reproduce if safe to provide, and a safe way to contact you. Do not include passwords, access tokens, government identifiers, bank details, or unrelated personal data in an initial report — we will provide a secure method if sensitive evidence is required.
For general data-handling information, see the Privacy Policy. Contractual rules for Customer use are in the Terms and Conditions.