Trust & compliance

Zahara Security

We take security seriously. From the Microsoft Azure platform Zahara runs on, to Cyber Essentials Plus certification, annual penetration testing and the controls around every login — your data is protected at every layer.

Security highlights

How we protect Zahara and your data

A clear set of platform, certification and access controls that customers ask about most often.

Hosted on Microsoft Azure

Built on Microsoft’s cloud platform for reliability and a strong security baseline.

Cyber Essentials Plus

Zahara Systems Ltd are Cyber Essentials Plus certified.

Local data export

All order and invoice line data can be downloaded to a local database.

Document return

All stored documents can be returned if you leave Zahara.

Two-factor authentication

An extra layer of protection on every sign-in.

Single sign-on

Sign in with Microsoft and Google SSO.

Password lockouts

Accounts lock after failed login attempts.

Password complexity

Strong password requirements are enforced.

Platform

Start with a great platform

Reliability and security begin with the cloud provider we build on.

There are four main cloud-based platforms in the world: Amazon Web Services (AWS), Microsoft Azure, Google and Alibaba. We have chosen to use Microsoft Azure as our code and database are heavily reliant on Microsoft's platform. Microsoft has been one of the pioneers of computing over the last 35 years and they go from strength to strength with their hosted model.

What we look for in a cloud provider is reliability and security. We operate Zahara safe in the knowledge that the platform it sits on is protected. It's a great base layer. It's then down to us to make sure our own boundary is secure, and having Cyber Essentials Plus certification helps us operate to a high standard. We then protect our clients' data as best we can — with two-factor authentication being an example of a new standard of protection that everyone is now offering or planning to offer.

Assurance

Our annual audit

Independent testing every year, with findings acted on by our developers.

Every year we undertake a penetration test. We use a third-party company to test for any vulnerabilities in Zahara's application. Results are then acted upon by the developers. We will never share the results with anyone who doesn't work for Zahara, but existing and prospective customers will appreciate that this process is undertaken annually.

  • Independent third-party penetration testing
  • Findings reviewed and remediated by our developers
  • Completed on an annual cycle

Resilience

Backup of data

Constant backups, UK datacentre mirroring and encrypted recovery points.

Zahara's data is in constant backup. The databases are mirrored in different UK datacentres so if one fails the other is available. Backups of these databases are then created every 15 minutes so we have the ability to go back in time and extract data in the event of a corruption. All backup databases are encrypted.

All of the documents you save in Zahara are stored in Azure storage. Microsoft Azure perform distributed backups so they are always made available to us.

  • Mirrored databases across UK datacentres
  • Encrypted backups every 15 minutes
  • Documents stored in Azure with distributed backups

Questions about Zahara security?

Speak to our team about hosting, certification, access controls or how we handle your data if you leave Zahara.