Security
Your invoice data is confidential. We treat it that way.
Every invoice and meter record you upload to Zevero is encrypted at rest and in transit. We operate on infrastructure aligned with ISO 27001 and store data in Singapore-region cloud facilities.
Data handling
What we store and how we store it
Encryption in transit and at rest
All data transfers use TLS 1.3. Invoice files and extracted ledger records are stored encrypted using AES-256. Encryption keys are managed through a hardware security module and rotated on a 90-day cycle.
Singapore-region infrastructure
Customer data is stored and processed in AWS ap-southeast-1. We do not move data outside the region. Backups are encrypted and stored in the same region with 30-day retention.
Retention and deletion
Invoice source files are retained for 12 months from upload. Extracted emission data is retained for the duration of your subscription. All data is permanently deleted within 30 days of account closure on request.
Access controls
Designed for multi-person finance teams
Role-based permissions
Assign Admin, Reviewer, or Read-only roles to each user. Admins manage integrations and billing. Reviewers can approve emission entries. Read-only users view reports without edit access.
Single sign-on support
Connect Zevero to your existing identity provider via SAML 2.0. SSO is available on Professional and Enterprise plans. Password-based login uses bcrypt hashing and supports TOTP two-factor authentication.
Audit log
Every login, data upload, emission entry edit, and report export is recorded in the audit log with user identity and timestamp. Logs are immutable and retained for 24 months.
Security questions before you sign up?
We are happy to share our full security documentation, answer due diligence questionnaires, or arrange a call with our engineering team. Contact us before you start your evaluation.