Zarv

Security is everything.

We process +3 TB of sensitive data daily. Security, privacy, and compliance aren't features — they're the foundation.

05 etapas

The path of one piece of data.

From collection to deletion, every step has a control — and none of them rests on trust.

  1. 1 · Collection

    Only what is needed

    We collect only the data the verification requires, for as long as it requires. In SmartFlow, the camera, liveness and document run on Zarv's domain and never pass through the customer's site.

    Minimization · origin isolation
  2. 2 · In transit

    Encrypted on the way

    Every exchange between your systems, Zarv and our services travels encrypted, in every environment.

    TLS 1.3
  3. 3 · At rest

    Encrypted where it sits

    Data lives in private networks on Google Cloud, with daily backups and point-in-time recovery.

    AES-256 · private VPC · daily backup
  4. 4 · Access

    Who accessed it, when and why

    Access is role-based with multi-factor authentication, and every query is written to an audit trail.

    RBAC · MFA · per-query trail
  5. 5 · Retention

    Deleted once it is no longer needed

    Retention follows your policy and the legal requirement, with automatic deletion at the end of the window. Data subject rights apply at any time.

    Auto-deletion · LGPD/GDPR rights

Auditable. Adherent. In progress.

Where we already adhere, and what is still in certification — stated item by item.

SOC 2 Type IIIn Progress

Annual third-party audits of our security, availability, and confidentiality controls.

ISO 27001In Progress

International standard for information security management systems.

LGPD CompliantCompliant

Full compliance with Brazil's General Data Protection Law.

GDPR ReadyCompliant

European data protection standards implemented across all products.

CCPA CompliantCompliant

California Consumer Privacy Act requirements met for US operations.

BrazilLGPDBC Resolution 4.658/2018SUSEP Circular 612/2020
European UnionGDPRePrivacy DirectiveNIS Directive
United StatesCCPAGLBAFCRA

Built to be unbreakable.

Data Encryption

AES-256 encryption at rest, TLS 1.3 in transit. All data encrypted end-to-end.

Network Isolation

Private VPCs, network segmentation, and zero-trust architecture across all services.

Access Control

Role-based access control (RBAC), multi-factor authentication, and audit logging.

DDoS Protection

Edge DDoS protection with automatic threat detection and mitigation.

Backup & Recovery

Automated daily backups with point-in-time recovery and 99.9% uptime SLA.

Monitoring

24/7 security monitoring, intrusion detection, and automated incident response.

Your data. Your rules.

We're the processor, never the owner.

1

Data Minimization

We only collect what we need, when we need it. No excessive data collection.

2

Purpose Limitation

Data is used only for specified, explicit purposes. No hidden secondary use.

3

Retention Limits

Automatic data deletion based on legal requirements and customer policies.

4

User Rights

Full LGPD/GDPR rights: access, rectification, erasure, portability, and objection.

The sensitive steps never touch your site.

In Zarv SmartFlow the signup runs inside your page, but the camera, liveness, one-time codes and personal data stay in a Zarv-hosted environment, open only to the origins you allow. It is the Stripe Checkout security model applied to identity.

Your siteYour brand, your domain, two lines of code.
Zarv's environmentCamera, liveness, document and personal data.
Your systemsGet the result over a signed webhook, with no personal data by default.

Security Testing

Regular security assessments and penetration testing.

Quarterly penetration tests by independent third-party security firms. Vulnerability scanning, code reviews, and security audits conducted continuously.

Incident Response

24/7 security operations center with defined incident response procedures.

Automated threat detection, immediate incident containment, and transparent communication protocols. All security incidents reported within required legal timeframes.

What your procurement team needs.

Sent on request, for any vendor assessment.

Questions from vendor reviews

Where is the data hosted?

On Zarv infrastructure in Google Cloud, in private networks, encrypted at rest and in transit.

Do you sign a DPA?

Yes. Request it at privacy@zarv.com, along with the subprocessor list.

How often do you run penetration tests?

Quarterly, by independent security firms, alongside continuous vulnerability scanning and code review.

How does incident response work?

24/7 monitoring, immediate containment and transparent communication. Incidents are reported within the legally required windows.

How do I report a vulnerability?

Write to security@zarv.com with the technical details. We answer every report and stay in touch through the fix.

Vulnerabilities

Found a flaw? Write to security@zarv.com

Documents and privacy

DPA, subprocessors and data subject rights: privacy@zarv.com

See risk before it costs you.

GDPR & CCPA Compliant · No commitment · Live in minutes