New Zato is live for accounting firms across Australia and New Zealand. See what’s new
ProductIntegrationsSecurityResourcesAboutContact
Book a Demo

Trust & Compliance

Security

Zato Privacy, Security & AI Governance Framework: ANZ. This document sets out the controls, standards and governance mechanisms Zato deploys to protect client data and maintain the trust of accounting firms.

Document

Zato Privacy, Security & AI Governance Framework: ANZ

Owner

Zato Origin Limited

Version

1.0 · Issued May 2026

Inquiries

security@zatohq.com

01: Scope and purpose

Scope and Purpose

This document sets out the controls, standards and governance mechanisms Zato deploys to protect client data and maintain the trust of accounting firms.

This framework applies to all Zato systems, personnel, sub-processors and third-party integrations that handle Client Personal Data or Firm Data as those terms are defined in Zato's Data Processing Agreement.

International standards referenced

Standard Role in Zato's compliance posture
ISO/IEC 27001:2022 Information Security Management System baseline expected by audit firms and corporate procurement teams.
SOC 2 Type II Independent attestation over Security, Availability, and Confidentiality controls.
ISO/IEC 42001:2023 Certifiable AI management standard that supports Zato's AI governance posture.
ISO/IEC 27701:2019 Privacy information management extension to ISO 27001.
ISO/IEC 27017 / 27018 Cloud control and privacy controls for public cloud environments.
NIST CSF 2.0 / NIST AI RMF 1.0 Taxonomy used for customer questionnaires and AI risk communication.

02: Regulatory perimeter

Regulatory Perimeter

Zato operates within a dual-jurisdiction regulatory framework, serving accounting firms in both Australia and New Zealand. Each jurisdiction has distinct privacy obligations that Zato addresses through aligned controls.

Australia

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs 1–13). Operational compliance.
  • Notifiable Data Breach scheme integrated into incident response procedures.
  • AML/CTF substrate support for accounting firm compliance obligations.

New Zealand

  • Privacy Act 2020 and Information Privacy Principles (IPPs 1–13). Operational compliance.
  • IPP 3A indirect collection notification paths and transfer-mapping controls.
  • AML/CFT substrate support for accounting firm compliance obligations.
  • Breach notification pathways established and tested.

03: Infrastructure & data residency

Infrastructure & Data Residency

Zato is built on AWS infrastructure with data residency controls that allow clients to elect the region in which their data is stored and processed.

Area Approach
New Zealand clients AWS Asia Pacific (New Zealand): ap-southeast-6, Auckland Region, with Bedrock and AgentCore available in-region.
Australian clients AWS Asia Pacific (Sydney): ap-southeast-2, as primary, with Melbourne available for recovery and supporting services.
Data plane Persistent stores, queues, backups, observability data, and audit logs remain in the tenant's elected region.
Model inference In-region inference by default. Where cross-region inference is required, routing is constrained to approved AU geographic profiles.

Cross-border data transfer controls

  • Comparable privacy safeguards across Australia and New Zealand are assessed before cross-border disclosures.
  • Contractual controls flow APP-equivalent and IPP-equivalent protections through DPAs and intra-group mechanisms.
  • Technical confinement allows customers to elect single-region residency where required.

04: Trust architecture

Trust Architecture

Zato's trust architecture is designed to protect client data at every layer of the stack, from identity and access management through to incident response.

Control family Implementation Reference
Identity & access SSO support, MFA, just-in-time elevation, and controlled service credentials. ISO 27001 A.5.15–A.5.18
Encryption TLS in transit, AES-256-GCM at rest, customer-managed keys where required. ISO 27001 A.8.24
Tenant isolation Per-tenant encryption keys and logically segregated processing boundaries. ISO 27017 / ISO 27018
Logging & monitoring Immutable event journaling, SIEM centralisation, alerting, and evidence retention. SOC 2 CC7.2
Vulnerability & patching Software composition analysis, SAST, DAST, penetration testing, and severity SLAs. ISO 27001 A.8.8 / A.8.29
Business continuity & DR Documented RPO/RTO, cross-AZ deployment, and annual recovery testing. ISO 22301 / SOC 2 A1.2
AI lifecycle AI impact assessments, prompt and model registry, evaluation, monitoring, and human review. ISO 42001 / NIST AI RMF
Incident response 24×7 response readiness with statutory-clock awareness across AU and NZ requirements. ISO 27001 A.5.24–A.5.28

05: AI & LLM concerns

AI & LLM Governance

Zato's agentic AI architecture introduces risks that require specific mitigation. The following table describes how Zato addresses each concern.

AI risks addressed

  • Training-data leakage and prompt injection
  • Cross-tenant context bleed and PII exposure in prompts
  • Hallucination, output integrity, and tool-execution risk
  • Auditability, model versioning, data egress, and availability risk
Concern Mitigation Technical support
Training-data leakage Customer inputs and outputs are not used to train foundation models under Bedrock privacy terms. Bedrock privacy commitments
Prompt injection Instruction/data separation, allowlisted tools, output validation, and guardrails. Bedrock Guardrails / Gateway policy
Cross-tenant bleed Per-tenant IAM identity, per-tenant memory, and tenant-scoped retrieval indices. AgentCore Identity / Memory
Hallucination Grounded generation, confidence checks, and escalation to human review when thresholds are not met. Contextual grounding / Zato orchestration
Auditability Each model invocation, tool call, and memory access is recorded in an append-only event journal. AgentCore Observability / CloudWatch
Data egress In-region inference by default, VPC endpoints, and constrained cross-region routing. Bedrock regional controls

06: Anonymisation & de-identification

Anonymisation & De-identification

Zato applies a layered transformation approach to reduce re-identification risk across different processing contexts.

Technique Use case
Suppression Remove fields that are not required downstream.
Masking Expose field presence without revealing sensitive values.
Generalisation Reduce granularity for analytics and low-risk processing.
Deterministic tokenisation Support joins without revealing source identifiers.
Format-preserving encryption Preserve value shape for systems that require specific formats.
Salted hashing Irreversible pseudonymisation when re-identification is never required.
Date shifting Preserve interval logic while obscuring absolute dates.
Synthetic data Non-production development, QA, and demonstration environments.

07: Certifications

Certifications

Zato is independently audited and certified across five international standards covering information security, AI governance, quality management, and personal data protection. Certificates and audit reports are available upon request.

Standard Coverage Status
ISO 9001 Quality management systems. Certified
ISO 27001:2022 Information security management systems. Certified
ISO 42001 Artificial intelligence management systems. Certified
GDPR Personal data protection (EU General Data Protection Regulation). Compliance statement
SOC 2 Security, availability, and confidentiality controls (AICPA). Independent attestation

All certificates and audit reports are available on request under NDA. Contact security@zatohq.com for copies and vendor due-diligence documentation.

08: Compliance matrix

Compliance Matrix

The following matrix summarises how Zato addresses each regulatory instrument and international standard relevant to ANZ accounting firms.

Instrument Jurisdiction Status How
Privacy Act 1988 · APPs 1–13 AU Operational APP-aligned privacy notice, APP 11 controls, and NDB integration into incident response.
Privacy Act 2020 · IPPs 1–13 NZ Operational IPP-aligned privacy practices and breach notification pathways.
IPP 3A: indirect collection NZ Operational Indirect collection notification paths and transfer-mapping controls.
AML/CTF / AML/CFT substrate AU / NZ Client-substrate ready Retention, evidence lineage, and workflow support for accounting firm compliance obligations.
ISO 9001 International Certified Quality management system certified to ISO 9001. Certificate available on request.
ISO/IEC 27001:2022 International Certified Information security management system independently audited and certified. Certificate available on request.
ISO/IEC 42001 International Certified AI management system independently audited and certified. Certificate available on request.
SOC 2 International Independent attestation Security, availability, and confidentiality controls independently attested. Report available on request under NDA.
GDPR EU Compliance statement Personal data protection controls independently audited against GDPR. Audit documentation available on request.
AWS underlying infrastructure International Inherited AWS attestations and certifications are reviewed through vendor management and available through AWS Artifact under NDA.

09: Compliance inquiries

Compliance Inquiries

Direct all compliance and privacy inquiries to the appropriate contact below. We aim to acknowledge all inquiries within one business day.

Area Contact
General trust & compliance security@zatohq.com. Vendor questionnaires, DPA requests, sub-processor disclosure, certification artefacts.
Security incident notification security@zatohq.com. Incidents involving Zato systems and coordinated disclosure.
Privacy & data subject requests security@zatohq.com. Access, correction, erasure, and cross-border transfer inquiries.
Regulatory authorities security@zatohq.com. Formal correspondence from competent authorities.

10: Compliance documents

Compliance Documents

Certificates and audit reports are released after review, and we keep a record of every release. Australian and New Zealand artefacts are certified and held separately, so tell us which entity your review covers.

AU Australia — Zato Australia Pty Ltd

Certificate

ISO/IEC 27001:2022

Information security management system certificate.

Audit report

SOC 2 Type II

Independent attestation over security, availability and confidentiality controls.

Certificate

ISO/IEC 42001:2023

AI management system certificate.

Certificate

ISO 9001:2015

Quality management system certificate.

Statement

GDPR

Data protection and lawful processing position.

NZ New Zealand — Zato New Zealand Limited

Certificate

ISO/IEC 27001:2022

Information security management system certificate.

Audit report

SOC 2 Type II

Independent attestation over security, availability and confidentiality controls.

Statement

GDPR

Data protection and lawful processing position.

Or pick individual documents above. We respond within two business days.

Request access

* Required

Tell us who you are and which documents you need. We review every request and send the documents through.

Documents requested *

Australia

New Zealand

Also available

Excel, Word, PDF or CSV. Send your standard vendor questionnaire and we will complete it.

Please add your name, a valid work email, your firm, a region and at least one document.

We respond to every request within two business days. Certificates and audit reports are released after review. Under our Data Processing Addendum, audit reports are Zato Confidential Information and are made available for review once per calendar year. See the DPA and security documentation.

11: Sub-processors

Sub-processors

The services that help us deliver and operate the platform. Customers can subscribe to change notifications by contacting security@zatohq.com.

SubprocessorPurposeData locationStatus
AWSCloud infrastructure, hosting, storage and in-region model inference.Australia (ap-southeast-2) and New Zealand (ap-southeast-6)Active
XeroAccounting ledger integration and client data sync.Australia and New ZealandActive
Microsoft Entra IDSingle sign-on identity provider.GlobalActive
GoogleWorkspace, identity, analytics and productivity services.GlobalActive
SerpAPIWeb search enrichment for Auto-Coding and agents.GlobalActive

Client data is stored and processed in the region the firm elects: AWS Asia Pacific (Sydney) ap-southeast-2 for Australian clients and AWS Asia Pacific (New Zealand) ap-southeast-6 for New Zealand clients, with model inference in-region by default. As disclosed in clause 8.1 of our Data Processing Addendum, Zato, its affiliates and its sub-processors may also process personal data in Australia, New Zealand and India. The current sub-processor list is available on request, and customers can subscribe to change notifications via security@zatohq.com.

12: Shared responsibility

Shared Responsibility

Security is a shared model. This is the line between what Zato operates and what remains with your firm.

AreaZatoYour firm
InfrastructureHosting, network controls, encryption in transit and at rest, patching and monitoring.Nothing. Managed entirely by Zato.
Application securitySecure development, testing, vulnerability management and release control.Reporting suspected issues to the security team.
Identity and accessSSO support, role based access control, authentication and audit logging.Deciding who gets access, assigning roles, and removing leavers promptly.
Client dataStoring and processing data in the elected region per the DPA.Accuracy and lawful basis for the data uploaded, and consents required from clients.
Output reviewProducing output, and the controls and audit trail around it.Professional review of output before it is relied on or filed.
Devices and endpointsZato-managed devices and personnel.Your own devices, email, endpoint protection and network.

13: Security reviews

Security Reviews

Submit your firm’s security questionnaire and our team will complete it.

Running a security review?

Submit your firm's security questionnaire through the Security centre and our team will complete it. Most standard questionnaires are answered from our existing control evidence, so turnaround is quick. If your reviewer needs something that is not covered here, ask and we will point you to the right artefact.

14: Terms of Use

Terms of Use

The Zato Terms of Use, together with the Data Processing Addendum and Appendix A (Technical and Organisational Security Measures), govern access to and use of the Zato platform. They cover provision of the Services, customer responsibilities, fees, proprietary rights, confidentiality, warranties, indemnification, limitation of liability, term and termination, and the contracting entity and governing law that apply in Australia and New Zealand.

The full and current text is published in one place so there is a single authoritative version.

Read the full Terms of Use