Least privilege
Administrative access is limited to what is necessary for the operation, security and support of the service, with separation of responsibilities where the architecture allows it.
ZebraByte Security
Security is treated as a continuous operational process.We implement risk-proportionate controls, limit access, reduce the area of attack, and design services so that prevention, detection and recovery work together.
Security principles
Concrete controls differ between services and suppliers. The principles below define the common direction without turning a technical practice into a universal promise for each product.
Administrative access is limited to what is necessary for the operation, security and support of the service, with separation of responsibilities where the architecture allows it.
We prefer declarative configurations, automation, versioning and change management processes to reduce manual interference and configuration derive.
We combine edge, identity, application, infrastructure and data controls, depending on the service and the risk we protect.
Dependencies, images, packages and delivery flows are treated as part of the attack surface and are managed through environmentally appropriate controls.
Logging, monitoring, alerting and anomaly signals are used to detect changes or behaviors that require investigation.
Data minimization, proportional retention and separation of processing roles are integrated into service design and operational processes.
Operational controls
Identity, edge, application, infrastructure, data and operating processes are treated as complementary layers.
MFA, access policies, privileges segregation and administrative access limitations are applied where the platform or service supports them.
TLS, edge filtration, rate limiting, WAF and other protective measures are used depending on the architecture, exposure and contracted service.
Configurations, patches and vulnerabilities are assessed and prioritized based on risk, impact and actual exploitability.
We use logical separation and access controls appropriate to the service. Data is encrypted in transit and, where the service and provider allow, in storage.
For services that include backup or disaster recovery, retention, restoration and recovery objectives are defined by the applicable plan and configuration.
Relevant events are correlated with triage, containment, repair and recovery processes, with escalation according to severity.
Technology & infrastructure ecosystem
We work with specialized organizations for connectivity, digital infrastructure, privacy and cybersecurity. Business relations and delivery architecture can vary between services; ZebraByte remains the contractual contact point for services provided directly to its customers.
Connectivity & enterprise IT
Partnership for business connectivity, IT and infrastructure solutions, used according to project requirements.
Cloud & hosting infrastructure
Technology partner for cloud, hosting and infrastructure components used in eligible ZebraByte services.
Web & digital infrastructure
Partnership in the Newfold ecosystem for selected web services, domains and digital infrastructure components.
Certified Partner · Privacy & compliance
Certified partnership for privacy, cookie consent and digital compliance components.
Cybersecurity
Partnership in the Xcitium ecosystem, formerly Comodo Security Solutions, for endpoint security technologies, Zero Trust and security services.
Infrastructure assurance
For certain eligible services, infrastructure components are provided through environments that maintain recognised certifications, accreditations or assurance reports.


These certifications, accreditations and trust marks apply only to infrastructure environments or relevant providers for eligible services. They are not presented as certifications issued directly to ZEBRABYTE LIMITED and do not extend the scope of a certification beyond the entity or infrastructure for which it was issued.
Vulnerability disclosure
If you have identified a security issue in a ZebraByte service, use formularul dedicat de raportareThe form requires email verification and complete technical details. For researchers and automated tools we continue to publish and security.txt.
For sufficiently detailed reports, the operational target is an initial response within approximately 24 hours, which does not constitute a contractual SLA.
Incident response
When an incident affects a customer’s data or services, communication and notifications are managed according to available facts, contractual obligations and applicable legal requirements.
Security also depends on the client-controlled configurations. Accounts, users, passwords, MFAs, apps, plugins, uploaded data and changes made to client-managed systems must be operated securely.
For managed services, the exact responsibilities are determined by the order, plan, SLA and applicable contractual documents.
Security information
Here we publish how we approach the security of ZebraByte services. Contractual terms, DPAs, SLAs and privacy policies areined separately in the Legal Center.
Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.