Security is everything.
We process +3 TB of sensitive data daily. Security, privacy, and compliance aren't features — they're the foundation.
The path of one piece of data.
From collection to deletion, every step has a control — and none of them rests on trust.
- 1 · Collection
Only what is needed
We collect only the data the verification requires, for as long as it requires. In SmartFlow, the camera, liveness and document run on Zarv's domain and never pass through the customer's site.
Minimization · origin isolation - 2 · In transit
Encrypted on the way
Every exchange between your systems, Zarv and our services travels encrypted, in every environment.
TLS 1.3 - 3 · At rest
Encrypted where it sits
Data lives in private networks on Google Cloud, with daily backups and point-in-time recovery.
AES-256 · private VPC · daily backup - 4 · Access
Who accessed it, when and why
Access is role-based with multi-factor authentication, and every query is written to an audit trail.
RBAC · MFA · per-query trail - 5 · Retention
Deleted once it is no longer needed
Retention follows your policy and the legal requirement, with automatic deletion at the end of the window. Data subject rights apply at any time.
Auto-deletion · LGPD/GDPR rights
Auditable. Adherent. In progress.
Where we already adhere, and what is still in certification — stated item by item.
Annual third-party audits of our security, availability, and confidentiality controls.
International standard for information security management systems.
Full compliance with Brazil's General Data Protection Law.
European data protection standards implemented across all products.
California Consumer Privacy Act requirements met for US operations.
Built to be unbreakable.
Data Encryption
AES-256 encryption at rest, TLS 1.3 in transit. All data encrypted end-to-end.
Network Isolation
Private VPCs, network segmentation, and zero-trust architecture across all services.
Access Control
Role-based access control (RBAC), multi-factor authentication, and audit logging.
DDoS Protection
Edge DDoS protection with automatic threat detection and mitigation.
Backup & Recovery
Automated daily backups with point-in-time recovery and 99.9% uptime SLA.
Monitoring
24/7 security monitoring, intrusion detection, and automated incident response.
Your data. Your rules.
We're the processor, never the owner.
Data Minimization
We only collect what we need, when we need it. No excessive data collection.
Purpose Limitation
Data is used only for specified, explicit purposes. No hidden secondary use.
Retention Limits
Automatic data deletion based on legal requirements and customer policies.
User Rights
Full LGPD/GDPR rights: access, rectification, erasure, portability, and objection.
The sensitive steps never touch your site.
In Zarv SmartFlow the signup runs inside your page, but the camera, liveness, one-time codes and personal data stay in a Zarv-hosted environment, open only to the origins you allow. It is the Stripe Checkout security model applied to identity.
Security Testing
Regular security assessments and penetration testing.
Quarterly penetration tests by independent third-party security firms. Vulnerability scanning, code reviews, and security audits conducted continuously.
Incident Response
24/7 security operations center with defined incident response procedures.
Automated threat detection, immediate incident containment, and transparent communication protocols. All security incidents reported within required legal timeframes.
What your procurement team needs.
Sent on request, for any vendor assessment.
Questions from vendor reviews
Where is the data hosted?
On Zarv infrastructure in Google Cloud, in private networks, encrypted at rest and in transit.
Do you sign a DPA?
Yes. Request it at privacy@zarv.com, along with the subprocessor list.
How often do you run penetration tests?
Quarterly, by independent security firms, alongside continuous vulnerability scanning and code review.
How does incident response work?
24/7 monitoring, immediate containment and transparent communication. Incidents are reported within the legally required windows.
How do I report a vulnerability?
Write to security@zarv.com with the technical details. We answer every report and stay in touch through the fix.
Found a flaw? Write to security@zarv.com
DPA, subprocessors and data subject rights: privacy@zarv.com
See risk before it costs you.
GDPR & CCPA Compliant · No commitment · Live in minutes