Secure connections
Production website and API traffic use HTTPS to protect information while it travels between your browser and Zeggai.
Account and session protection
- Passwords are stored using a modern one-way password hash rather than as readable passwords.
- Email verification, short-lived access tokens, rotating refresh sessions, secure cookies, logout, and password reset controls protect account access.
- Sensitive authentication routes use rate limits, and production session requests are checked against approved website origins.
Roles and tenant isolation
Zeggai checks authenticated business membership and roles before allowing protected operations. Business, store, product, upload, analysis, and report queries are scoped to the active business so one tenant cannot request another tenant's records.
Application safeguards
- Request validation and upload size/type limits reduce malformed or unsafe input.
- Security headers, controlled cross-origin access, structured error handling, and duplicate protections are applied by the backend.
- Audit timestamps and actor fields are maintained on business-critical records, with soft deletion used where safe recovery or auditability matters.
Monitoring and incident response
Zeggai records structured operational logs and uses error monitoring without enabling default personal-information collection. Passwords, tokens, cookies, and raw uploaded files are excluded from normal application logs.
If we confirm a security incident affecting personal data, we will assess it, take containment and recovery steps, and communicate as required by applicable law.
Your role
Use a unique password, protect account access, assign roles carefully, log out from shared devices, and contact support@zeggai.com promptly if you suspect unauthorised activity.
Need help?
Contact us and include enough detail for us to understand your request.
Report a security concern