# ZebraByte Cloud

**ZebraByte Cloud** is the production delivery model for the platform. ZebraByte hosts and operates the application, ships updates and security fixes, and manages the underlying platform infrastructure so customers and professional advisers can focus on the compliance program rather than application operations.

ZebraByte is not distributed as an open-source or customer-operated self-hosted edition.

## Who can use ZebraByte Cloud

The same SaaS platform supports several operating models:

- **Companies and internal teams** can run their own compliance program.
- **Professional advisers** such as lawyers, DPOs, GRC consultants and compliance specialists can use the platform as the operating environment for client work.
- **Managed Compliance customers** can have ZebraByte specialists run more of the compliance workload on the same platform.

## What ZebraByte operates

At platform level, ZebraByte is responsible for areas such as:

- application hosting and platform updates;
- infrastructure maintenance and security patching;
- platform data storage and backup controls;
- service monitoring and operational maintenance;
- network, encryption and secret-management controls used by the SaaS service;
- the platform integration and automation layer.

Exact contractual commitments, availability, recovery objectives, retention and customer-specific controls are governed by the applicable ZebraByte service agreement and Compliance Portal material.

## Shared responsibility

| **ZebraByte platform responsibilities** | **Customer / professional responsibilities** |
| --- | --- |
| Hosting, updates, platform backups, infrastructure security and service monitoring | Users, roles, SSO/SCIM configuration, business approvals and appropriate use of the platform |
| Protecting platform infrastructure and service credentials | Deciding which integrations to authorize and who receives administrative access |
| Maintaining the SaaS application and supported integration layer | Providing accurate organizational information, evidence and control ownership |
| Operating platform-level recovery and security processes | Operating the customer's own systems, source data and business continuity obligations |

With **Managed Compliance**, ZebraByte can additionally take responsibility for agreed compliance operations such as evidence coordination, policy work, remediation tracking and audit preparation. That service-layer responsibility is separate from the cloud infrastructure boundary above.

## Security and privacy

- [Infrastructure security](/docs/deployment/infrastructure-security) — Review high-level platform security controls and isolation boundaries
- [Integration credentials](/docs/product/access-review/integration-security) — How connected-system API keys and OAuth tokens are handled
- [Compliance Portal](/docs/product/compliance-portal) — Share approved security and compliance information through controlled access

## Cloud SaaS vs historical deployment references

The docs include preserved Docker Compose and Kubernetes pages from the platform's technical lineage. They document useful architecture assumptions around databases, object storage, secrets, ingress, monitoring and upgrades.

Those pages are **reference material only**. ZebraByte customers do not clone a repository, install a Helm chart or operate the application stack themselves.

- [Architecture & migration reference](/docs/deployment/self-hosting) — Review the preserved deployment lineage without treating it as a ZebraByte installation path
- [Choose an operating model](/docs/product/getting-started/choose-deployment) — Compare self-service, professional/adviser use and Managed Compliance

## Get ZebraByte Cloud

To discuss onboarding, professional use, security review requirements or Managed Compliance, [contact ZebraByte](/demo).
