Security Overview
Zimmic — ZLabs S.R.L., together with its affiliated companies Zimmic LLC and Zimmic E.A.S. — operates an Information Security Management System (ISMS) built on the confidentiality, integrity, and availability of information. This overview describes the security practices Zimmic applies to protect the information entrusted to us by customers, collaborators, and suppliers.
Information Security Management System
Zimmic maintains an ISMS aligned with ISO/IEC 27001. Management establishes an annual plan for the ISMS in line with the organization's mission and vision, defines a documented methodology to identify and manage information security risks and opportunities, and reviews the security policy annually to keep it effective and continuously improving.
All Zimmic collaborators are responsible for identifying, documenting, and reporting any suspected or confirmed security breach or non-compliance, following defined procedures.
ISO/IEC 27001 Certification
Zimmic is ISO/IEC 27001 certified and commits to complying with the requirements of the standard in its current version. ISO/IEC 27001 is an internationally recognized information security standard that specifies security management best practices and comprehensive security controls.
Identity and Access Management
- Access to systems and information is granted under the principle of least privilege.
- Access rights are assigned based on role and responsibility.
- Multi-factor authentication is used where applicable to protect access to systems that store or process sensitive information.
- Access rights are reviewed periodically to confirm they remain appropriate, and are removed when no longer needed.
Encryption
Information is encrypted in transit using industry-standard protocols such as TLS. Encryption at rest is applied where applicable, depending on the systems and services involved.
Infrastructure and Network Protections
Zimmic applies infrastructure and network safeguards designed to reduce the exposure of the systems it operates, including network access restrictions and system hardening. Where services are delivered within customer or third-party environments, Zimmic works within the security controls established for those environments.
Monitoring and Logging
Zimmic uses monitoring and logging practices designed to support the detection, investigation, and resolution of security events in the systems it operates.
Secure Software Development
Security is considered throughout the software development lifecycle:
- Code review: changes are reviewed before being integrated.
- Change management: changes follow a controlled process from development through deployment.
- Dependency management: third-party dependencies are tracked and kept up to date.
- Secret management: credentials, keys, and other secrets are managed so they are not exposed in source code or deliverables.
Vulnerability Management
Zimmic works to identify and remediate vulnerabilities in the systems it operates, prioritizing remediation based on severity and exposure. Reports from external security researchers are welcome under our Responsible Disclosure Policy.
Incident Response
Zimmic maintains a defined methodology for identifying, documenting, and applying corrective actions to security incidents, including events of divergence, omission, or negligence affecting the services provided by the organization. When an incident affects customer information, Zimmic communicates with affected customers in accordance with contractual and legal obligations.
Business Continuity and Backups
Management defines the means necessary to ensure business continuity under contingency events, including backup practices for the information and systems Zimmic operates.
Third-Party Risk Management
The information technology tools and services Zimmic uses are expected to align with the objectives and policies of the ISMS. Tools that do not fully comply, but whose use is identified as necessary for the business, are permitted only under strict, recurring controls. See our Subprocessors page for how third parties may be engaged in service delivery.
Customer Responsibilities
Security is a shared responsibility. Customers remain responsible for:
- The security configuration and administration of the systems and platforms they own, including their own Salesforce and cloud environments, except where otherwise agreed in a services contract.
- Managing their own user accounts, access rights, and credentials.
- The content and lawfulness of the data they choose to share with Zimmic.
Security Contact
For security questions or to report a concern, contact security@zimmic.com. To report a vulnerability, please follow our Responsible Disclosure Policy.
Evidence of applicable security practices and certifications may be provided upon request and, where appropriate, under a non-disclosure agreement.



