Tenant and role isolation
Business records are scoped to the owning workspace. Role-aware authorization limits access to customer, payment, accounting and administrative functions.
Security
This page describes the controls Zivo currently operates and states clearly where independent assurance is still pending.
Business records are scoped to the owning workspace. Role-aware authorization limits access to customer, payment, accounting and administrative functions.
Application secrets and connected-service credentials are stored outside public pages, sensitive values are masked in administrative screens and access is limited to authorized operators.
ZivoPay keeps transaction references, callback results and ledger activity attached to the correct business. Public payment links use non-sequential secure tokens.
Administrative actions, invoice changes, payment states and delivery activity retain attributable records for investigation and reconciliation.
Production data is backed up and deploy procedures include migration safeguards, cache clearing and worker restarts. Recovery procedures are reviewed as the platform changes.
Potential vulnerabilities can be reported privately to muki@zama.co.ke. Reports should include affected URLs, reproduction steps and impact; do not access or alter other customers’ data.
Independent assurance register
Zivo does not claim SOC 2, ISO 27001, PCI DSS certification or an independent penetration-test result without a current, verifiable report. When an assessment is completed, this page will publish the assessor, scope, completion date and a customer-safe summary.
Report a security concern