Skip to content
Security & privacy

Your staff trust you with their data. We take that seriously.

Phone numbers, pay rates, contracts, sick records - a rota app holds sensitive things. Here is exactly how Zero protects them.

How it works

Eight things we do about it

No badges, no jargon - just the measures that are actually in the product today, and what each one means for your staff.

Every organisation isolated

Row-level security walls each organisation off inside the database itself - a query from one organisation cannot return another’s rows, even in theory.

35+ granular permissions

In-app permissions control exactly who sees what. Pay rates and contracts are additionally gated at the database layer, so even a crafted query can’t leak them.

Hosted in the EU

Your data lives on Supabase - managed Postgres hosted in the EU. Professional database infrastructure, kept in-region.

Encrypted everywhere

Every connection between the app and our servers is encrypted with TLS, and data is encrypted at rest on disk.

Personal data, need-to-know

Staff phone numbers and emergency contacts are restricted to managers through dedicated access rules - never part of general staff data.

Documents kept private

Contracts, certificates and IDs sit in private storage buckets. Files are only reachable through time-limited signed links - there are no public URLs.

Payments handled by Stripe

Card details go straight to Stripe and never touch our servers. We see that you’ve paid - not your card number.

Locked on the phone too

Sign-in runs on Supabase Auth, with an optional Face ID or fingerprint lock on the app itself. Offline changes queue safely on-device until they sync.

UK GDPR

Your data, your rules

Zero is aligned with UK GDPR, and the principle behind it is simple: the data in your account belongs to your business and your staff - we just look after it. You stay in control of where it goes and how long it stays.

Want the detail? The full picture is in our privacy policy.

  • Export anytime

    Take a full copy of your organisation’s data whenever you like - it’s yours, not ours.

  • Deletion on request

    Ask and we delete - your whole organisation or a single member of staff.

  • Never sold

    We don’t sell data, share it with brokers, or monetise it in any way beyond your subscription.

  • No ad tracking

    No advertising pixels, no third-party trackers following your staff around the web.

Where we are

An honest note from a small team

Zero is a young product in beta, built by a small team - and we would rather tell you that plainly than hide behind a wall of badges. We do not yet hold SOC 2 or ISO 27001 certification, and we won’t pretend otherwise.

What you get instead is a direct line. Security questions are answered by the people who wrote the code - not a support tier reading from a script. If something about our setup matters to your due diligence, ask us and we will show you how it works.

Ask us a security question

Diligence done? Try it properly.

See how Zero handles your team’s data first-hand. Free for 30 days - no card, no catch.