# Zenda | Security & Compliance

> How Shockoe secures the Zenda hospitality platform: AWS + Cloudflare hosting, encryption in transit and at rest, least-privilege access, responsible disclosure, and current certification status.

https://zenda.cx/security

# Security & Compliance

Last updated: August 30, 2026

Security is fundamental to an enterprise hospitality platform. This page summarizes how Shockoe protects the Zenda product and this website. For privacy and data-rights questions, see our Privacy Policy.

## Hosting and infrastructure

Zenda runs on Amazon Web Services (AWS). This marketing website is served as static content from AWS with Cloudflare in front for content delivery, DNS, and DDoS protection. Our infrastructure providers operate US-based data centres that maintain their own independent compliance programs, including SOC 2 and ISO 27001.

## Encryption

All network traffic is encrypted in transit using TLS 1.2 or higher. Data at rest in our cloud infrastructure is encrypted using industry-standard AES-256 through our providers’ managed storage services.

## Access control

Shockoe personnel are granted least-privilege access to production systems, multi-factor authentication is required for administrative access, and access is reviewed periodically and revoked promptly when no longer needed. Within the Zenda product, single sign-on (SSO/SAML), role-based access control, and audit logging are available to customers depending on configuration.

## Environment separation

Production is isolated from development and test environments. Infrastructure is managed as code so that changes are reviewed, versioned, and reproducible.

## Data handling

Zenda is integration-first and is designed to store the minimum guest data required to orchestrate the systems a property already operates. Customers control what data flows through their deployment. Payment card data is processed by PCI-compliant payment providers and is not stored by Zenda in cardholder form.

## Resilience and backups

The production platform uses multi-availability-zone infrastructure and automated backups to support recovery from failures.

## Vulnerability management

We monitor our software dependencies for known vulnerabilities and patch on a risk-prioritized basis. The platform undergoes periodic security testing.

## Responsible disclosure

If you believe you have found a security vulnerability affecting Zenda or this website, please email website@shockoe.com with enough detail for us to reproduce it. We ask that you give us a reasonable opportunity to investigate and remediate before disclosing publicly. We will not pursue legal action against researchers who act in good faith and avoid privacy violations, service disruption, and data destruction.

## Incident response

We maintain a documented process to detect, contain, investigate, and remediate security incidents. If an incident affects a customer’s data, we will notify the affected customer without undue delay in accordance with our contractual commitments and applicable law.

## Sub-processors

We rely on a small set of vetted service providers — HubSpot, Google, Amazon Web Services, and Cloudflare. See the Privacy Policy for what each one processes.

## Certifications

Shockoe does not currently hold a SOC 2, ISO 27001, or comparable third-party security certification for Zenda, and none is in progress at this time. We rely on the attestations of our infrastructure providers and on the controls described above. We will update this page if that changes.

## Contact

Security and privacy questions: website@shockoe.com

Is my data encrypted?

Yes. All traffic to and from Zenda and this website is encrypted in transit with TLS 1.2 or higher, and data at rest in our cloud infrastructure is encrypted using industry-standard AES-256.

Where is Zenda hosted?

Zenda runs on Amazon Web Services in the United States, with Cloudflare providing content delivery, DNS, and DDoS protection. AWS data centres carry their own independent compliance attestations such as SOC 2 and ISO 27001.

How do I report a security vulnerability?

Email website@shockoe.com with the details. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We do not pursue legal action against researchers acting in good faith.
