Zivo Invoice. Track expenses. See your money.
Menu

Security

Controls you can review. Assurance claims you can verify.

This page describes the controls Zivo currently operates and states clearly where independent assurance is still pending.

Tenant and role isolation

Business records are scoped to the owning workspace. Role-aware authorization limits access to customer, payment, accounting and administrative functions.

Credential protection

Application secrets and connected-service credentials are stored outside public pages, sensitive values are masked in administrative screens and access is limited to authorized operators.

Payment integrity

ZivoPay keeps transaction references, callback results and ledger activity attached to the correct business. Public payment links use non-sequential secure tokens.

Audit and operational records

Administrative actions, invoice changes, payment states and delivery activity retain attributable records for investigation and reconciliation.

Backups and recovery

Production data is backed up and deploy procedures include migration safeguards, cache clearing and worker restarts. Recovery procedures are reviewed as the platform changes.

Responsible disclosure

Potential vulnerabilities can be reported privately to muki@zama.co.ke. Reports should include affected URLs, reproduction steps and impact; do not access or alter other customers’ data.

Independent assurance register

No third-party penetration-test report or security certification is currently published.

Zivo does not claim SOC 2, ISO 27001, PCI DSS certification or an independent penetration-test result without a current, verifiable report. When an assessment is completed, this page will publish the assessor, scope, completion date and a customer-safe summary.

Report a security concern