Zipline is Apache 2.0. Read every line. SOC 2 Type II audited, HIPAA-ready, FedRAMP In Process. Data never leaves your network - Zipline runs in your infrastructure.
Audited annually by an independent firm. Controls cover availability, security, confidentiality, and processing integrity. Report available under NDA.
Zipline runs in your VPC. Data flows source to sink inside your network. Nothing passes through Zipline's infrastructure. Your data is yours, full stop.
Bring your own encryption keys for secrets, config, and audit logs. Revoke access instantly. Keys are never stored by Zipline - managed entirely in your KMS.
Every line of the connector engine is on GitHub under Apache 2.0. Security by transparency, not obscurity. Fork it, audit it, contribute to it.
Give teams exactly the access they need. Not more. SSO, SCIM, per-connector RBAC, and a full audit trail - all included on every plan.
Finance, healthcare, government - Zipline meets you where your compliance requirements are. Documentation available for your security team on request.
Independently audited every year. Covers all five trust service criteria. Full report available under NDA.
Report under NDABusiness Associate Agreement available on the Enterprise plan. Technical safeguards, audit controls, and transmission security included.
BAA availableAuthorization In Process at the Moderate impact level. Working with a 3PAO toward full authorization in 2026.
In ProcessData Processing Agreement available. EU data residency options supported. Sub-processors list published and updated quarterly.
DPA availableWe take security reports seriously and respond to every submission within 24 hours. Please do not open a public GitHub issue for security vulnerabilities. Instead, contact us directly so we can assess and patch before disclosure. We follow coordinated disclosure - we'll work with you on a timeline that gives us time to fix while crediting your discovery.