Security
Identity, access and audit controls
Each control is implemented in a named product and open to inspection. Written for the person completing a vendor security review.
- Single sign-on
- SAML 2.0 and OIDC
- Access control
- Per object, per action, per row
- Report an issue
- support@zambrite.com
Identity stays in your directory
Zambrite CRM and ZedSign authenticate against your own identity provider rather than holding a separate password. Provisioning, password policy and de-provisioning happen where you already manage them, so a leaver loses access the moment your directory says so.
- 01SAML 2.0 and OIDC single sign-on (Zambrite CRM, ZedSign)
- 02Signing and approval routing bound to teams, groups and roles (ZedSign)
- 03Custom workspace domains (Zambrite CRM)
Authorisation down to the record
Access in Zambrite CRM is scoped rather than global. A role is defined per object and per action, and record visibility is enforced at the row, so a salesperson sees their own accounts and not the whole book.
- 01Roles scoped per object and per action
- 02Row-level security on customer records
- 03Separate, isolated business workspaces (Mesa)
- 04Configurable data and event retention (Zambrite CRM)
Audit history on every agreement
ZedSign records who an agreement went to, what they did with it and when. That history is what an audit or a dispute is settled from, and it ships with the product rather than as an upgrade.
Payment data never reaches us
Card payments run through Lipila’s hosted checkout, so card numbers are never received or stored by Zambrite. Mobile money settles directly with MTN, Airtel and Zamtel. All sites and products are served over HTTPS.
Reporting a vulnerability
Send it to support@zambrite.com with enough detail to reproduce it. We confirm receipt and tell you what we find. Report in good faith and you will hear nothing from a lawyer.
Running a vendor review?
Send it over and we will answer every line as written, including the ones where the answer is no.