ZestRecon
Trust & Security
Built for the teams who have to say yes before anyone connects real data.
Last updated: July 13, 2026
Enterprise and public-sector security teams don't take a vendor's word for it — they check identity controls, access boundaries, and audit coverage before a single credential gets connected. This page covers what's actually built into ZestRecon today, in the same terms your security review will ask about. It's a summary, not an exhaustive technical specification; for a security questionnaire or deeper technical review, contact us directly.
What Your Security Review Will Find
Federated identity, least-privilege access, and a full audit trail — enforced server-side.
We haven't completed a formal third-party certification (SOC 2, ISO 27001, FedRAMP) or an external penetration test yet, and we won't claim otherwise. If your procurement process requires one of these, tell us your timeline at info@zestcyber.com and we'll work with you on it directly.
Tenant isolation
Customer workspaces are tenant-scoped: data, findings, connectors, and reports for one workspace are not accessible from another. Access to a workspace requires authentication and is governed by role-based permissions configured by the workspace's administrators.
Encryption
Data is encrypted in transit using TLS. Sensitive credentials and secrets (such as connector tokens and API keys) are stored using one-way hashing or encrypted secret storage rather than in plain text, and full secret values are only ever displayed once, at creation time.
Access controls
Internal access to production systems is limited to personnel who need it to operate the Service, and is logged. Customer-facing accounts support role-based access control, and we recommend enabling multi-factor authentication and reviewing team membership and API key inventories regularly from the Administration section of the app.
Authorized scanning only
ZestRecon only assesses assets that a Customer has connected under its own authorized scope, as described in our Terms of Service. Assessment activity is scoped, logged, and available to Customer through the platform's audit log.
Vulnerability disclosure
If you believe you have discovered a security vulnerability in the ZestRecon platform or website, please report it to info@zestcyber.com. Include enough detail for us to reproduce the issue. We ask that you avoid accessing or modifying data that is not your own and give us a reasonable opportunity to investigate and remediate before public disclosure.
Incident response
We maintain an internal process for triaging and responding to security events affecting the Service. If an incident is determined to have affected Customer Data, we will notify affected customers in accordance with our contractual and legal obligations.
Contact us
For security questions or to report an issue, contact info@zestcyber.com or call (346) 235-5062.