SECURITY· Built for trust. Engineered for scale.
SOC 2 Type II, ISO 27001, ISO 27017 and PCI DSS — audited independently and kept current. Underneath them: end-to-end encryption, sign-in with nothing to phish, and permissions enforced on every single request.
Trusted by 1,000+ Brands Messaging Millions Daily
Encrypted in transit. Encrypted at rest.
Your customer data is protected by the same primitives a bank runs on — and the keys that unlock it never sit in the same place as the data they unlock.
contact.update
2.4 KB payload · workspace acme_8f2a
Handshake
Protocol
TLS 1.3
Cipher
AES-256-GCM
HSTS
1 year · preload
Nothing to phish. Nothing to leak.
There is no password to reuse, guess, or hand to a convincing lookalike. Sign-in is bound to a device, an inbox, or your own identity provider — and it ends the moment your directory says it should.
Touch ID to continue as [email protected]
Credential never leaves the device
The private key sits in the secure enclave. Zixflow only ever sees a signature.
Meanwhile, on the lookalike
Captured from passkey sign-in
Total haul: nothing usable
Every credential here is scoped to the real origin and to one device or one inbox. There is no secret sitting in a database waiting to be reused somewhere else.
Who can do what — and proof of who did.
Permissions are not a tidy settings page you hope someone reads. They decide what every request is allowed to return, and every decision they make is written down.
Roles · workspace acme
server-enforcedSigned in as [email protected] · Support
Audit trail
append-onlyNothing here can be edited or deleted, including by us.
The controls an enterprise buyer, a bank's risk team and a regulator each want to see before they let a messaging platform near their customers.
Hardening
Scrubbing, a WAF, rate limits, a mutually authenticated service mesh and per-tenant isolation. A request has to clear every layer, and any one of them can end it.
Five layers. A request has to clear every one of them.
Privacy
Export, erasure and rectification run from the dashboard across profiles, events, message history and backups — with a signed record of exactly what was touched and when.
Residency
Pick a region at setup and customer data lives there. Nothing is quietly replicated somewhere else to make a query faster.
Assurance
SOC 2 Type II, ISO 27001, ISO 27017 and PCI DSS, kept current — reports available under NDA.
Verifying SOC 2 Type II…
Monitoring
Infrastructure is monitored continuously for credential stuffing, unusual export volume and traffic spikes. Suspicious sessions are contained automatically and the owner is told.
auth.passkey.verified · ap-south-1
api.rate_limit.applied · 300 req/min
export.requested · approved by owner
auth.failed × 47 · single /24 range
24/7
monitored
400d
log retention
Administration
SSO, SCIM provisioning, IP allowlists, session limits and key rotation are org-wide policy — applied to every member at once, not a checkbox each of them can find.
Applying org policy…