Legal
Data Security Policy
Technical and organisational controls Zerix applies to protect client data at rest, in transit and in operation.
Last updated: 1 October 2025
Zerix maintains high information security and data protection standards. Client data resides on enterprise-grade managed cloud infrastructure within the EU (Ireland) region, meeting UK GDPR and EU data residency requirements.
Key controls
- AES-256 encryption at rest and TLS 1.2+ encryption in transit.
- Automated daily backups, retained for 30 days and securely stored within the same region.
- Access controls and role-based permissions applied to all accounts.
- Multi-factor authentication (2FA) enabled for administrative and developer accounts.
- Regular security patching and dependency monitoring on all hosted environments.
Zerix never sells, shares or transfers client data to any third parties without explicit consent or lawful basis.