Home
Product
About
Get started
Log in
Get Started with Zato

Zato Security

Accounting firms trust Zato with the most sensitive data they hold — their clients' financial records. We don't take that lightly.

Security and privacy aren't features in Zato. They're the foundation every other feature is built on. Your firm retains full ownership and control of your client data. Zato processes that information for one reason only: to run your accounting workflows.

Zato AI Policy

Service-Only Processing

Data processed within Zato is used solely to operate the platform and deliver accounting workflows.

Human Oversight

Accounting professionals remain responsible for reviewing platform outputs and decisions.

Traceable Platform Actions

System activity and automated outputs are logged to support transparency and review

No Data Selling or Sharing

Firm and client data is never sold, shared, or monetised.

Secure Data Handling

AI functionality operates within the same security and access controls as the core platform.

Controlled Integrations

External integrations access data only when enabled and authorised by the accounting firm.

Platform Security

Encrypted Data

All platform communications are encrypted in transit using secure TLS protocols.

Access Controls

Role-based permissions ensure users only access information relevant to their role.

Tenant Separation

Customer environments are logically separated to protect firm and client data.

Secure Infrastructure

Zato operates on enterprise-grade cloud infrastructure with continuous monitoring.

Authentication Controls

Robust authentication and account access controls protect platform users.

Automated Backups

Encrypted backups support resilience and recovery of platform data.

Infrastructure & Hosting

Cloud Infrastructure

Zato runs on secure Amazon Web Services infrastructure designed for reliability, scalability, and enterprise-grade security.

Regional Data Hosting

Customer data is always hosted locally, with New Zealand data stored in New Zealand and Australian data stored in Australia.

Operational Monitoring

Infrastructure and platform systems are continuously monitored to maintain availability, reliability, and security for our clients.

Additional documentation

Compliance documents are available upon request.

For any enquiries

Contact security@zatohq.com

Make Zato your unfair advantage.

Get started with Zato today
HomeAboutProductSecurityTerms of Use
SecurityPrivacy policyTerms of service

We take data protection seriously. Our platform is built to ISO 9001, ISO 27001 and ISO 42001 standards, is SOC 2 compliant, and fully GDPR compliant—ensuring enterprise-grade security, privacy, and responsible AI governance across all data.