Security

Enterprise security, open source transparency.

Zipline is Apache 2.0. Read every line. SOC 2 Type II audited, HIPAA-ready, FedRAMP In Process. Data never leaves your network - Zipline runs in your infrastructure.

View compliance docs Report a vulnerability

SOC 2 Type II

Audited annually by an independent firm. Controls cover availability, security, confidentiality, and processing integrity. Report available under NDA.

No data egress

Zipline runs in your VPC. Data flows source to sink inside your network. Nothing passes through Zipline's infrastructure. Your data is yours, full stop.

CMEK

Bring your own encryption keys for secrets, config, and audit logs. Revoke access instantly. Keys are never stored by Zipline - managed entirely in your KMS.

Open source

Every line of the connector engine is on GitHub under Apache 2.0. Security by transparency, not obscurity. Fork it, audit it, contribute to it.

Granular access control

Give teams exactly the access they need. Not more. SSO, SCIM, per-connector RBAC, and a full audit trail - all included on every plan.

SSO / SAML Supports Okta, Azure AD, and Google Workspace. One-click setup with metadata import.
SCIM provisioning Users sync automatically from your IdP. Deprovision instantly when someone leaves - no manual cleanup.
Per-connector RBAC Assign read, write, or admin permissions at the individual connector level. Different teams, different access.
Scoped API keys Generate keys with narrowly scoped permissions and mandatory expiry dates. No long-lived root credentials.
Full audit log Every action logged with user identity, timestamp, source IP, and result. Exportable to your SIEM in real time.

Built for regulated industries

Finance, healthcare, government - Zipline meets you where your compliance requirements are. Documentation available for your security team on request.

SOC 2 Type II

Independently audited every year. Covers all five trust service criteria. Full report available under NDA.

Report under NDA

HIPAA

Business Associate Agreement available on the Enterprise plan. Technical safeguards, audit controls, and transmission security included.

BAA available

FedRAMP

Authorization In Process at the Moderate impact level. Working with a 3PAO toward full authorization in 2026.

In Process

GDPR

Data Processing Agreement available. EU data residency options supported. Sub-processors list published and updated quarterly.

DPA available

Found a vulnerability?

We take security reports seriously and respond to every submission within 24 hours. Please do not open a public GitHub issue for security vulnerabilities. Instead, contact us directly so we can assess and patch before disclosure. We follow coordinated disclosure - we'll work with you on a timeline that gives us time to fix while crediting your discovery.

Bug bounty program PGP public key

Take security off the checklist.

Everything your security team needs - reports, questionnaires, DPAs - ready to go.