Security

Your data is safe with us

We built ZiggyPayroll for our own business first. Security was never optional.

Two-Factor Authentication (TOTP)

Protect your account with time-based one-time passwords via any authenticator app.

Data Encrypted at Rest (AES-256)

All stored data is encrypted using AES-256 — the same standard used by financial institutions.

Data Encrypted in Transit (TLS 1.3)

All data in transit is protected using TLS 1.3 — the latest transport security protocol.

SOC 2 Compliance (In Progress)

We are working toward SOC 2 Type II certification. Our infrastructure is built to meet its requirements.

PCI Compliant Payments (Stripe)

We never store card data. All billing is handled by Stripe, a Level 1 PCI DSS compliant processor.

Row-Level Security

Your data is isolated at the database level. No other customer can access your data under any circumstances.

GDPR & CCPA Compliant

Data subject access requests, deletion requests, and portability exports are all supported.

Regular Security Audits

We conduct periodic security reviews of our infrastructure, code, and access controls.

Questions about security?

We're happy to answer before you sign up.

Start Free Trial