Security & Compliance Documentation Request Policy

Effective 2026-08-31 · Version 1.0

1. Purpose of This Document

This policy sets out the terms, procedures, and controls that govern the request, receipt, review, and use of security and compliance documentation relating to the ZynReach platform.

This policy is intended to strike a balance between the following objectives:

This policy forms part of ZynReach's overall governance, security, and compliance framework.

  • Enabling prospective and existing customers to carry out appropriate security and legal due diligence.
  • Providing the information necessary to assess data protection and information security controls.
  • Protecting confidential and sensitive information relating to ZynReach's internal infrastructure, technologies, and processes.
  • Preventing unauthorized disclosure of information that could affect the security of the platform or its customers.
  • Preventing the use of ZynReach documents outside the purpose for which they were provided.
  • Preserving the rights of ZynReach, Zyntra Digital, its service providers, partners, and third parties.
  • Ensuring that information provided to customers is subject to a structured review and disclosure process.

2. Scope of Application

This policy applies to all requests for documents or information relating to the following areas, as well as to requests submitted by the parties listed below:

  • Information security.
  • Data protection.
  • Privacy.
  • Compliance.
  • Risk management.
  • Business continuity.
  • Disaster recovery.
  • Security incident management.
  • Infrastructure.
  • Vendors and sub-processors.
  • Customer data access practices.
  • Identity and access controls.
  • Audit logs.
  • Encryption.
  • Backups.
  • Security testing.
  • Review and assessment processes.
  • The Data Processing Agreement.
  • Enterprise due-diligence documentation.
  • Requests from existing customers.
  • Requests from prospective customers.
  • Requests from procurement teams.
  • Requests from cybersecurity teams.
  • Requests from Legal & Compliance teams.
  • Requests from data protection officers.
  • Requests from customer-appointed auditors.
  • Requests from enterprise partners.
  • Requests from legal or security advisors authorized by the customer.

3. Nature of Security & Compliance Documents

ZynReach recognizes that some customers, particularly Enterprise-tier customers, need to carry out a security and legal review before or during contracting.

Accordingly, depending on the nature of the request and the applicable level of authorization, ZynReach may make available some or all of the following documents, organized across three tiers:

Tier One — Public Documents: this tier includes documents that are published or otherwise publicly available, as listed below. A dedicated security and compliance page, together with a DPA covering data processing, is currently available on the website.

Tier Two — Due-Diligence Documents: these may be provided following review of the request, and cover the following areas as applicable.

Tier Three — Restricted Documents: these documents may require legal approval, verification of the requesting party's identity, an NDA, and a legitimate business justification. Depending on the circumstances, they may include the following.

  • Tier One — Security Overview.
  • Tier One — Privacy Policy.
  • Tier One — Data Processing Agreement.
  • Tier One — Compliance Overview.
  • Tier One — Sub-processor Information.
  • Tier One — Data Residency Information.
  • Tier One — Security Practices Overview.
  • Tier Two — Security Questionnaire.
  • Tier Two — Privacy Questionnaire.
  • Tier Two — Compliance Questionnaire.
  • Tier Two — Technical & Organizational Measures (TOMs).
  • Tier Two — Business Continuity Overview.
  • Tier Two — Disaster Recovery Overview.
  • Tier Two — Incident Response Overview.
  • Tier Two — Access Control Overview.
  • Tier Two — Encryption Overview.
  • Tier Two — Vulnerability Management Overview.
  • Tier Two — Security Testing Summary.
  • Tier Two — Data Flow Overview.
  • Tier Two — Sub-processor Details.
  • Tier Two — Data Residency Information.
  • Tier Three — Independent audit or assessment reports.
  • Tier Three — Security testing reports.
  • Tier Three — Security Assessment Reports.
  • Tier Three — Penetration Testing Executive Summary.
  • Tier Three — Detailed Security Architecture Information.
  • Tier Three — Disaster Recovery Test Summary.
  • Tier Three — Detailed Control Evidence.
  • Tier Three — Auditor Reports.
  • Tier Three — Sensitive technical documentation.

4. Information ZynReach Is Not Obligated to Disclose

For security, commercial, and legal reasons, ZynReach reserves the right to refuse, restrict, or redact any request that involves information that could increase security risk or expose trade secrets.

This includes, without limitation:

ZynReach may provide a redacted version or an executive summary in place of disclosing the original details.

  • Passwords.
  • Encryption keys.
  • API keys.
  • Access tokens.
  • Credentials.
  • Secrets.
  • Infrastructure keys.
  • Firewall rule details.
  • Details of sensitive internal networks.
  • Sensitive internal addresses or endpoints.
  • Protection mechanisms that could be exploited to bypass controls.
  • Customer data.
  • Personal data not necessary for the assessment.
  • Identifying information about unauthorized personnel.
  • Details of unremediated vulnerabilities that could lead to direct exploitation.
  • Undisclosed source code.
  • Trade secrets.
  • Information relating to other customers.
  • Information relating to service providers where subject to contractual restrictions.

5. Security Documents Are Not Automatically Disclosed

Submitting a request form on the website does not automatically create a right to receive any or all of ZynReach's security, technical, or legal documents.

ZynReach reserves the right to:

Non-disclosure of a particular document is not considered a refusal to comply, unless an express contractual or legal obligation to disclose it exists.

  • Review the request.
  • Verify the identity of the requester.
  • Verify the entity the requester represents.
  • Assess the purpose of the request.
  • Determine the appropriate level of information.
  • Request additional documentation.
  • Request execution of an NDA.
  • Require a valid contractual agreement.
  • Refuse the request in whole or in part.
  • Provide a redacted version of the document.
  • Provide an alternative summary.

6. Verifying the Requester's Identity

For the purpose of protecting ZynReach and its customers, the company may request information to verify the requester's identity, including:

Requests for restricted documents from anonymous or non-professional email addresses are not preferred to be accepted without additional verification.

  • Full name.
  • Job title.
  • Company name.
  • Professional email address.
  • Country.
  • Purpose of the request.
  • Nature of the relationship with ZynReach.
  • Name of the customer or enterprise account, where applicable.

7. Business/Professional Email

For Enterprise requests, or requests involving restricted documents, ZynReach may require the use of a corporate email address belonging to the requesting organization.

A request may be refused or deferred if it cannot be reasonably verified that the requester represents the organization it claims to represent.

8. Non-Disclosure Agreement (NDA)

ZynReach may require execution of a Non-Disclosure Agreement (NDA) before disclosing any documents or information classified as one of the following categories:

In such cases, disclosure does not take effect until the required approval and signature formalities have been completed.

  • Confidential.
  • Restricted.
  • Highly Confidential.

9. Use of Documents

Where any security document or information is provided, the receiving party is granted a limited, non-exclusive, non-transferable right to use it solely for the purpose of conducting the security, legal, and commercial evaluation of ZynReach and its prospective or existing contractual relationship with the receiving party.

The documents may not be used for any of the following purposes without ZynReach's prior written consent:

  • For marketing purposes.
  • For competitive purposes.
  • For resale.
  • For public publication.
  • For upload to public websites.
  • For sharing with unauthorized parties.
  • For evaluating a competitor.
  • For use in press materials.
  • As independent evidence of another organization's compliance.

10. Prohibition on Republication

Restricted security and compliance documents may not be copied, republished, or distributed, in whole or in part, without ZynReach's prior written consent.

This includes:

  • Websites.
  • GitHub.
  • Public repositories.
  • Social media.
  • Forums.
  • Public presentations.
  • Published procurement reports.
  • Press reports.
  • Public documents.

11. Third-Party-Issued Documents

ZynReach documents may include information, reports, certifications, or assessments issued by independent bodies or third parties. In such cases:

  • The document is not considered to be the exclusive property of ZynReach.
  • Its use is subject to any restrictions imposed by its owner.
  • It may not be interpreted in a manner that exceeds its original scope.
  • ZynReach may not amend the content of a report issued by an independent party in a way that alters its meaning.

12. Certifications, Frameworks & Standards

ZynReach uses terminology such as the following frameworks to describe its security and compliance program, and each description must be interpreted according to its actual status, scope, and date:

In particular:

"Certified" means that a valid, formal certification issued by an appropriate accreditation or certification body exists, where that is the actual status.

"Audited" means that the controls or system have undergone an audit within the scope specified in the report.

"Aligned" means that the practices or controls are designed or organized to be consistent with, or to follow, a given framework, and does not by itself mean that certification has been obtained.

"Ready" means that processes or practices are designed to support the requirements of the relevant framework, and does not by itself mean that ZynReach has obtained a formal certification or accreditation.

This distinction is legally significant, because ZynReach's own current website uses phrasing such as SOC 2 Type II, ISO 27001 aligned, and GDPR-ready rather than presenting all of these frameworks as equivalent certifications in nature.

  • SOC 2 Type II.
  • ISO 27001 aligned.
  • GDPR-ready.
  • CCPA.

14. Protection of Personal Data During the Request Process

ZynReach is committed to processing personal data submitted as part of a security and compliance documentation request in accordance with its Privacy Policy and applicable law.

The information provided is used, as applicable, for the following purposes:

The requester must not submit any sensitive personal data or actual customer data that is not expressly required.

  • Processing the request.
  • Verifying identity.
  • Communicating with the requester.
  • Managing the due-diligence process.
  • Complying with legal obligations.
  • Documenting approvals.
  • Managing business relationships.

15. Processing of Customer Data

Where ZynReach processes personal data on behalf of a customer, the relationship governing that data processing may be subject to a separate Data Processing Agreement (DPA).

ZynReach's currently published DPA provides that data processing is carried out in accordance with the customer's documented instructions, together with provisions addressing sub-processors, security measures, data subject rights, and international transfers.

16. Sub-processors

ZynReach may use service providers or sub-processors to operate the platform, including:

Sub-processors and the scope of their use are identified in the documents published or made available to customers, subject to the applicable legal and contractual obligations.

  • Cloud infrastructure.
  • Email delivery.
  • Analytics.
  • Customer support.

17. International Data Transfer

Data may be processed or stored in different geographic locations depending on the infrastructure, plan, and services used.

ZynReach's current compliance information indicates that customer data is by default hosted in data centers within the United States, with regional data residency options available for Enterprise plans as contractually agreed.

Any international transfer of data, where applicable, is subject to the appropriate legal and contractual safeguards and controls.

18. Security Incident Management

ZynReach maintains a framework for managing and responding to security incidents that includes, as applicable to the incident, the following steps:

The current security page refers to a documented incident response plan, defined severity and escalation levels, and frameworks for notifying customers in accordance with applicable regulatory requirements.

  • Incident detection.
  • Severity classification.
  • Containment.
  • Investigation.
  • Remediation.
  • Recovery.
  • Root cause analysis.
  • Corrective actions.
  • Notification of affected parties where required by law or contract.

19. Security as an Ongoing Process

ZynReach does not guarantee that any information system can be absolutely immune to all risks or threats.

Accordingly, any reference to "Secure / Security / Protected / Enterprise-grade" must be understood as a description of the security controls and practices applied, and not as an absolute guarantee against the occurrence of:

This wording is very important to protect the company from having marketing language interpreted as an absolute guarantee of a security outcome.

  • A breach.
  • Data loss.
  • Service interruption.
  • Human error.
  • A cyberattack.
  • A security vulnerability.

20. Backup & Recovery

ZynReach uses backup, restoration, and disaster recovery mechanisms in accordance with its adopted operational architecture.

However, the existence of backups must not be interpreted as an absolute guarantee against any data loss under all circumstances.

Recovery capability depends on the nature and scope of the incident, the data affected, the infrastructure involved, and the recovery procedures in place.

21. Customer Obligations

When using ZynReach, the customer remains responsible for:

  • Protecting its own login credentials.
  • Not sharing passwords.
  • Enabling MFA wherever available.
  • Managing user permissions.
  • Removing unauthorized users.
  • Not uploading unlawful data.
  • Not using the platform to infringe the rights of others.
  • Complying with the laws applicable to its activity.
  • Determining the data it is entitled to input into the platform.
  • Applying appropriate data retention controls.

22. ZynReach Is Not a Substitute for Customer Security Responsibilities

Use of ZynReach does not transfer all cybersecurity or data protection responsibilities to ZynReach.

Each party's responsibilities are governed by:

The relationship is regarded as a Shared Responsibility Model, depending on the nature of the service and its use.

  • The service agreement.
  • The DPA, where applicable.
  • The Privacy Policy.
  • The Terms of Service.
  • Commercial agreements.
  • Applicable laws and regulations.

23. Obligations of the Customer's Review Team

When the customer obtains restricted documents, it must:

  • Limit access to individuals who need it.
  • Protect the documents from unauthorized access.
  • Not copy or publish them outside the permitted purpose.
  • Not use them to conduct offensive testing against ZynReach.
  • Not attempt to discover or exploit vulnerabilities based on the information provided.
  • Notify ZynReach if the documents are sent to an unauthorized person.
  • Comply with any applicable NDA or confidentiality agreement.

24. Prohibition on Unauthorized Offensive Testing

Providing security or technical documents is not to be regarded as consent to:

No security testing may be conducted on ZynReach's systems except under prior, express written authorization from ZynReach specifying the scope, duration, and systems permitted to be tested.

  • Penetration testing.
  • Vulnerability scanning.
  • Load testing.
  • Security testing.
  • Automated scanning.
  • Reverse engineering.
  • Exploitation attempts.

25. Document Request Procedure

The request process follows seven consecutive stages:

Stage 1 — Submitting the Request: the user provides the following information.

Stage 2 — Verification: ZynReach reviews the request to verify the following elements.

Stage 3 — Classification: the request is classified as Public / Confidential / Restricted according to the nature of the information.

Stage 4 — NDA: where required, the confidentiality agreement is completed.

Stage 5 — Approval: internal approval is obtained according to the sensitivity level of the documents.

Stage 6 — Disclosure: the documents are sent through the approved method.

Stage 7 — Recordkeeping: ZynReach may retain a record of the request and disclosure for governance and audit purposes.

  • Stage 1 — Name.
  • Stage 1 — Company.
  • Stage 1 — Corporate email.
  • Stage 1 — Job title.
  • Stage 1 — Type of documents requested.
  • Stage 1 — Purpose of the request.
  • Stage 2 — Identity of the requester.
  • Stage 2 — The organization represented.
  • Stage 2 — The purpose.
  • Stage 2 — The appropriate level of information.

26. Request Processing Time

ZynReach aims to process requests within a reasonable period appropriate to the nature of the request and the level of documentation requested.

No estimated timeframe constitutes a contractual promise unless expressly agreed in a written agreement.

Processing time may be extended in cases requiring:

  • Legal approval.
  • Security review.
  • An NDA.
  • Third-party consent.
  • Redaction of sensitive information.
  • Additional verification of the requester's identity.

27. Document Accuracy & Currency

Some security documents or audit reports may relate to a specific period of time.

Accordingly, a document must always be read together with its issue date, scope, and validity period, if any.

An outdated document may not be used to demonstrate a current security posture without verifying that it remains in effect.

28. Changes to the Security Program

ZynReach reserves the right to develop and update:

Certain information contained in security documents may change as the platform evolves.

  • Security architecture.
  • Controls.
  • Service providers.
  • Risk management procedures.
  • Incident response processes.
  • Encryption technologies.
  • Access policies.
  • Backup procedures.
  • Compliance procedures.

29. No Additional Guarantees Created

No security document, response to a security questionnaire, presentation, or email correspondence creates any additional contractual obligation on ZynReach unless expressly included in a written agreement signed by authorized representatives of the parties.

This point is very important for the company, so that an employee's answer to a Security Questionnaire does not become an independent legal commitment.

30. Conflicts Between Documents

In the event of a conflict between the following documents:

Order of precedence is determined by the applicable contractual agreements between the parties and the governing law.

In particular, this policy is not a substitute for the DPA, the service agreement, or any written commercial agreement.

  • This policy.
  • Security Documentation.
  • The Privacy Policy.
  • The DPA.
  • The Terms of Service.
  • The Master Service Agreement.

31. Intellectual Property Rights

All intellectual property rights relating to ZynReach's documents, including the following, remain the property of ZynReach or the relevant rights holders, unless a written agreement provides otherwise:

Delivery of a copy of a document does not transfer its intellectual property rights to the recipient.

  • Content.
  • Designs.
  • Tables.
  • Templates.
  • Graphics.
  • Security whitepapers.
  • Technical documentation.
  • Methodologies.

32. Notification of Leaked or Lost Documents

If a recipient becomes aware that a confidential or restricted ZynReach document has experienced any of the following:

It must notify ZynReach without undue delay through official communication channels.

  • Been lost.
  • Been stolen.
  • Been accessed without authorization.
  • Been sent to an unauthorized person.
  • Been published unintentionally.

33. ZynReach's Right to Amend or Withdraw Documents

ZynReach reserves the right to:

The existence of a prior version does not guarantee that it remains valid for use.

  • Update documents.
  • Replace documents.
  • Withdraw a document.
  • Correct an error.
  • Reclassify a document.
  • Restrict access to a document.
  • Issue a new version.

34. No Absolute Security Guarantee

While applying appropriate technical and organizational controls, ZynReach acknowledges that information security is affected by the evolving nature of risks, technologies, and threats.

Accordingly, ZynReach does not provide any absolute guarantee that the service will be free of all vulnerabilities, attacks, failures, or security incidents.

Any specific contractual warranties are governed exclusively by the commercial agreement signed between the parties.

35. Governing Law & Jurisdiction

This policy is governed, to the extent permitted by law, by the law applicable to the contractual relationship between ZynReach and the beneficiary organization.

Where a master agreement, DPA, or other agreement in effect specifies the governing law and jurisdiction, the provisions of that agreement shall govern in this respect.

36. Contacting the Security & Compliance Team & Requester Acknowledgment

To request security and compliance documentation or related inquiries, for legal inquiries, and for privacy and data protection requests, the following teams may be contacted:

ZynReach's current documents also display legal and privacy channels, including legal@zynreach.com and privacy@zynreach.com.

Requester Acknowledgment: by submitting a request to obtain security and compliance documentation, the requester acknowledges the following:

I acknowledge that the requested information may include confidential or restricted information, and I undertake to use any information provided by ZynReach solely for the purposes of legitimate security, legal, and commercial evaluation, and not to copy, publish, or share it with any unauthorized party, and to comply with any applicable non-disclosure agreement or terms of use. I further acknowledge that obtaining these documents does not constitute a guarantee or certification of legal compliance in favor of the requesting organization, and does not create any additional contractual obligation on ZynReach unless agreed in writing.

  • Security & Compliance Team — security@zynreach.com.
  • Legal Team — legal@zynreach.com.
  • Privacy Team — privacy@zynreach.com.

37. Disclaimer

The security and compliance information provided by ZynReach is intended to help customers and interested parties conduct appropriate due diligence.

This information does not constitute an absolute guarantee of security or compliance, and does not replace the independent legal or security assessment that may be required depending on the nature of the customer's business.

Any certifications, audits, or compliance frameworks referenced are limited by their scope, period, and issuing body, and may not be interpreted beyond that scope.

For privacy-related requests, contact us at privacy@zynreach.com.