# ZebraByte Cloud Infrastructure Security

This page provides a high-level overview of security controls for **ZebraByte Cloud**. Detailed architecture, operational procedures, and audit evidence are shared through the [Compliance Portal](https://trust.zebrabyte.ro) or during a security review.

## Data and tenant isolation

ZebraByte Cloud is available in separate EU and US regions. Your organization’s data is stored in the region selected during onboarding.

Customer organizations are logically isolated through tenant-scoped authorization and data access controls. Regional infrastructure is shared across Cloud customers and is not dedicated hardware for each organization.

## Security controls

- **Network boundaries** restrict direct access to application workloads and data services.
- **Encryption** protects data in transit and at rest. Sensitive application fields receive additional application-level encryption.
- **Secret management** keeps service credentials separate from application data and limits access according to operational roles.
- **Access control** applies least-privilege permissions to infrastructure and production operations.
- **Monitoring** supports detection and response for service and infrastructure events.

## Backups and recovery

ZebraByte Cloud uses encrypted daily backups and point-in-time recovery (PITR) with a five-minute recovery point objective. Backup retention, restoration procedures, and availability commitments are defined in applicable agreements and security documentation.

## Customer access

- Organization owners and administrators control membership, roles, and integrations.
- Stored integration credentials are not displayed back to users.
- Security concerns can be reported to [security@the platform.com](mailto:security@the platform.com).

## Shared responsibility

These controls apply to **ZebraByte Cloud**. In a [self-hosted deployment](/docs/deployment/self-hosting), your organization is responsible for infrastructure security, encryption, secrets, backups, monitoring, and production access.

## Security documentation

For subprocessors, certifications, control details, and audit artifacts, see the [Compliance Portal](https://trust.zebrabyte.ro). The [Privacy Policy](https://www.zebrabyte.ro/privacy) describes data processing and retention.

## Related documentation

- [ZebraByte Cloud](/docs/deployment/cloud)
- [How the platform Protects Integration Credentials](/docs/product/access-review/integration-security)
- [Privacy Policy](https://www.zebrabyte.ro/privacy)
- [Compliance Portal](https://trust.zebrabyte.ro)
