Statutory Documentation

Security & Infrastructure Architecture

Effective Date: January 1, 2026Last Modified: March 15, 2026
A comprehensive technical overview of Zeva Labs' defensive security controls, encryption benchmarks, cloud isolation, and incident management procedures.

1. Cloud Architecture & Infrastructure Defense

Zeva Accounts is deployed in redundant, high-availability enterprise cloud data centers located in India, engineered to ensure continuous operational availability and fault tolerance.

Public-facing traffic terminates at hardened enterprise load balancers with Web Application Firewall (WAF) rules active to prevent SQL injection, cross-site scripting (XSS), credential stuffing, and automated DDoS attacks.

All application backends and databases reside in isolated private networks with no direct public internet exposure. Outbound access is strictly mediated through secure stateful gateways.

2. Cryptographic Protocols & Key Management

Data in Transit: Modern TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) preloading. Weak cipher suites and legacy protocols are rejected at the edge.

Data at Rest: All production databases, system snapshots, and stored file attachments are encrypted at rest using industry-standard AES-256 with managed cryptographic keys subject to periodic rotation.

Credential Protection: User authentication credentials and passwords are protected using advanced cryptographic hashing algorithms with strict work factors.

3. Comprehensive Audit Trails & Immutability

Zeva Accounts maintains an immutable audit log for every critical transaction: invoice creation, credit note modification, ledger voucher reversal, user permission elevation, and tax return filing.

Audit logs capture user identity, organization context, timestamp in UTC, client IP, and payload verification metadata, streamed to protected, write-once storage to prevent tampering.

4. Vulnerability Scanning & Independent Assessments

We perform continuous automated dependency vulnerability scanning across all software repositories.

Independent third-party cybersecurity firms conduct periodic grey-box penetration tests across our web applications, mobile APIs, and cloud infrastructure. Penetration test summaries and compliance reports are available to enterprise clients under mutual NDA.