Skip to main content

ZebraByte Security

How we protect our services and data.

Security is treated as a continuous operational process.We implement risk-proportionate controls, limit access, reduce the area of attack, and design services so that prevention, detection and recovery work together.

Security principles

The principles that guide the way we operate.

Concrete controls differ between services and suppliers. The principles below define the common direction without turning a technical practice into a universal promise for each product.

Least privilege

Administrative access is limited to what is necessary for the operation, security and support of the service, with separation of responsibilities where the architecture allows it.

controlled changes

We prefer declarative configurations, automation, versioning and change management processes to reduce manual interference and configuration derive.

Defense in depth

We combine edge, identity, application, infrastructure and data controls, depending on the service and the risk we protect.

Supply-chain security

Dependencies, images, packages and delivery flows are treated as part of the attack surface and are managed through environmentally appropriate controls.

Observability

Logging, monitoring, alerting and anomaly signals are used to detect changes or behaviors that require investigation.

Privacy by design

Data minimization, proportional retention and separation of processing roles are integrated into service design and operational processes.

Operational controls

Security pe mai multe straturi.

Identity, edge, application, infrastructure, data and operating processes are treated as complementary layers.

01

Identity and Access

MFA, access policies, privileges segregation and administrative access limitations are applied where the platform or service supports them.

02

Traffic and Application Protection

TLS, edge filtration, rate limiting, WAF and other protective measures are used depending on the architecture, exposure and contracted service.

03

Hardening and Vulnerabilities

Configurations, patches and vulnerabilities are assessed and prioritized based on risk, impact and actual exploitability.

04

Data and segregation

We use logical separation and access controls appropriate to the service. Data is encrypted in transit and, where the service and provider allow, in storage.

05

Backup and Recovery

For services that include backup or disaster recovery, retention, restoration and recovery objectives are defined by the applicable plan and configuration.

06

Monitoring and response

Relevant events are correlated with triage, containment, repair and recovery processes, with escalation according to severity.

Technology & infrastructure ecosystem

Partnerships that expand the capabilities of ZebraByte.

We work with specialized organizations for connectivity, digital infrastructure, privacy and cybersecurity. Business relations and delivery architecture can vary between services; ZebraByte remains the contractual contact point for services provided directly to its customers.

ZEBRABYTE LIMITED — Telekom B2B Business Partner

Connectivity & enterprise IT

Telekom Business Partner

Partnership for business connectivity, IT and infrastructure solutions, used according to project requirements.

20i

Cloud & hosting infrastructure

20i

Technology partner for cloud, hosting and infrastructure components used in eligible ZebraByte services.

Newfold Digital

Web & digital infrastructure

Newfold Digital

Partnership in the Newfold ecosystem for selected web services, domains and digital infrastructure components.

iubenda Bronze Certified Partner

Certified Partner · Privacy & compliance

iubenda

Certified partnership for privacy, cookie consent and digital compliance components.

Xcitium

Cybersecurity

Xcitium

Partnership in the Xcitium ecosystem, formerly Comodo Security Solutions, for endpoint security technologies, Zero Trust and security services.

Infrastructure assurance

Accreditations and trust marks of the relevant infrastructure.

For certain eligible services, infrastructure components are provided through environments that maintain recognised certifications, accreditations or assurance reports.

ISO 9001ISO 22301ISO/IEC 27001ISAE 3000 SOC 2 Type IICyber Essentials PlusPCI DSS

These certifications, accreditations and trust marks apply only to infrastructure environments or relevant providers for eligible services. They are not presented as certifications issued directly to ZEBRABYTE LIMITED and do not extend the scope of a certification beyond the entity or infrastructure for which it was issued.

Vulnerability disclosure

Responsible reporting of vulnerabilities.

If you have identified a security issue in a ZebraByte service, use formularul dedicat de raportareThe form requires email verification and complete technical details. For researchers and automated tools we continue to publish and security.txt.

For sufficiently detailed reports, the operational target is an initial response within approximately 24 hours, which does not constitute a contractual SLA.

Rules for Responsible Testing

  • Test only ZebraByte systems that you are authorized to test and avoid third-party systems that are outside our control.
  • Do not access, copy or extract more data than is strictly necessary to demonstrate the problem.
  • It does not maintain persistence, does not modify or delete data and does not carry out denial-of-service attacks or actions that degrade the service.
  • It provides sufficient details for reproduction: the affected asset, the steps, the impact observed and a minimum of technical evidence.

Incident response

Detection, isolation, repair and recovery.

When an incident affects a customer’s data or services, communication and notifications are managed according to available facts, contractual obligations and applicable legal requirements.

Shared responsibility

Security also depends on the client-controlled configurations. Accounts, users, passwords, MFAs, apps, plugins, uploaded data and changes made to client-managed systems must be operated securely.

For managed services, the exact responsibilities are determined by the order, plan, SLA and applicable contractual documents.

Security information

A page on operational security ZebraByte.

Here we publish how we approach the security of ZebraByte services. Contractual terms, DPAs, SLAs and privacy policies areined separately in the Legal Center.

ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert