ZoSwitch
Security

Secure by design. From day one.

Every website, app and system we build is protected by default. Here is how we keep your data, and your business, safe.

Book your free discovery session

Not sure where to start? Most clients begin with a free conversation.

Zoho Authorised PartnerEncrypted by defaultUK GDPR alignedRegistered with the ICOISO 27001 & SOC 2 certified infrastructureRegistered UK company
How we protect your data

Built in, not bolted on.

These protections are part of everything we deliver, with nothing extra to set up.

Encrypted connections

All data travels over secure, encrypted connections (HTTPS), between your users, your systems and ours.

Encrypted storage

Your data is encrypted when it is stored, not only when it moves.

Protection from attacks

Built-in protection against floods of malicious traffic, and a web firewall that blocks common attacks before they reach your systems.

Strict access control

Access is set by role, so each person only sees the data they need for their job.

Secure sign-in

Modern, secure login, with two-step verification available for extra protection.

Regular automated backups

Your data is backed up automatically, so it can be restored if something goes wrong.

Hosted where you need it

We host your systems and data in the region that suits your business, whether that is the UK, the EU or elsewhere.

Trusted infrastructure

We build on infrastructure from providers certified to recognised security standards, including ISO 27001 and SOC 2.

Privacy and compliance

Your data, handled properly.

UK GDPR in mind

Systems are designed with UK GDPR in mind, including consent, data export and deletion where you need them.

Your data stays yours

Ownership of your data and the software we build is agreed in writing before any work starts.

Data processing agreement

A data processing agreement is available on request, setting out exactly how your data is handled.

Confidentiality

Happy to sign a non-disclosure agreement before you share anything sensitive.

After launch

Kept safe as you grow.

Security does not stop at go-live. Your team is trained to use each system safely, and you can raise any concern through your dedicated support portal. As your business changes, we can review who has access and keep everything working as it should.

Questions

Security questions.

Where will our data be hosted?+

In the region that suits your business, whether that is the UK, the EU or elsewhere. We agree this with you at the start.

Is our data encrypted?+

Yes. Data is encrypted while it travels between your users and your systems (HTTPS), and while it is stored.

Who can access our data?+

Only the people who need it. Access is set by role, so your team sees what they need for their job, and we only access your data when it is needed to build, fix or support your systems.

Is our data backed up?+

Yes. Your data is backed up automatically on a regular basis, so it can be restored if something goes wrong.

How are our systems protected from attacks?+

Your websites and systems sit behind built-in protection against floods of malicious traffic, and a web firewall that blocks common attacks before they reach them.

Can our team use two-step verification?+

Yes. Two-step verification is available on the sign-in for the systems we build, adding an extra layer of protection to every account.

What happens if there is a security incident?+

We would tell you promptly, work with you to contain it and support you in meeting your UK GDPR obligations, including reporting it where required.

Do you use other companies to process our data?+

Only trusted providers that we need to deliver our services, such as hosting, working under contract and only on our instructions.

Can we get a copy of our data, or have it deleted?+

Yes. You can ask for an export of your data at any time, and we can delete it when it is no longer needed, in line with our agreement with you.

What happens to our data if we stop working with you?+

Your data stays yours. We hand it over in a usable format and remove our access, so nothing is left behind.

Do you work in line with UK GDPR?+

Yes. We design systems with UK GDPR in mind and handle personal data only as needed to deliver our services. A data processing agreement is available on request.

Will you sign an NDA?+

Yes. If you would like to share sensitive information, we are happy to sign a non-disclosure agreement first.

Can you complete our security questionnaire?+

Yes. We are happy to answer your security or due-diligence questions as part of our proposal.

Not sure where to start?

That is exactly what the discovery session is for. Tell us where you are and where you want to be, and we will recommend the right combination.