Security · Zinye suite

Security, plainly stated.

Every Zinye product runs on dedicated servers we manage on Hetzner in the EU (Germany and Finland). We're an early-stage company, and this page says what we do today. It doesn't list badges we haven't earned.

Where we stand today

What we do, and what we don't have yet.

⚿

Hosting and access.

Customer sites run on dedicated servers in the EU. Traffic to Zinye is encrypted in transit with TLS. Staff access to infrastructure is restricted to the people who run it.

EU hosting · Hetzner TLS in transit Restricted admin access
◈

Your data, exportable.

Zinye runs on standard ERPNext and Frappe, so your data stays in an open schema. You can export it from the UI in standard formats whenever you like. We back sites up as part of managed hosting.

Open schema Export any time Managed backups
◐

Certifications: not yet.

Zinye is not SOC 2, ISO 27001, HIPAA or PCI-DSS certified, and we haven't completed third-party security audits. When that changes, we'll publish the report and the date here.

No certifications yet No third-party audits yet
↻

NRS e-invoicing connection.

For Nigerian e-invoicing, invoices go to the NRS through an NRS-accredited Access Point Provider partner. The accreditation belongs to the APP; Zinye handles the integration and your account setup.

Accredited APP partner NRS Merchant Buyer Solution
Commitments

Things we'll never do.

01

Sell your data.

Your transaction data isn't a product. We don't sell it, and we don't share it with advertisers.

02

Hold your data hostage.

Export your data any time from the UI. Standard ERPNext schema. If you leave, you take it with you.

03

Hide a problem from you.

If something goes wrong that affects your data, we'll tell you directly and explain what happened.

Security questionnaire
or DPA request?

Email support@zinye.com and the founder will answer directly. We'll tell you exactly what we do and don't have in place.