Your staff trust you with their data. We take that seriously.
Phone numbers, pay rates, contracts, sick records - a rota app holds sensitive things. Here is exactly how Zero protects them.
Eight things we do about it
No badges, no jargon - just the measures that are actually in the product today, and what each one means for your staff.
Every organisation isolated
Row-level security walls each organisation off inside the database itself - a query from one organisation cannot return another’s rows, even in theory.
35+ granular permissions
In-app permissions control exactly who sees what. Pay rates and contracts are additionally gated at the database layer, so even a crafted query can’t leak them.
Hosted in the EU
Your data lives on Supabase - managed Postgres hosted in the EU. Professional database infrastructure, kept in-region.
Encrypted everywhere
Every connection between the app and our servers is encrypted with TLS, and data is encrypted at rest on disk.
Personal data, need-to-know
Staff phone numbers and emergency contacts are restricted to managers through dedicated access rules - never part of general staff data.
Documents kept private
Contracts, certificates and IDs sit in private storage buckets. Files are only reachable through time-limited signed links - there are no public URLs.
Payments handled by Stripe
Card details go straight to Stripe and never touch our servers. We see that you’ve paid - not your card number.
Locked on the phone too
Sign-in runs on Supabase Auth, with an optional Face ID or fingerprint lock on the app itself. Offline changes queue safely on-device until they sync.
Your data, your rules
Zero is aligned with UK GDPR, and the principle behind it is simple: the data in your account belongs to your business and your staff - we just look after it. You stay in control of where it goes and how long it stays.
Want the detail? The full picture is in our privacy policy.
Export anytime
Take a full copy of your organisation’s data whenever you like - it’s yours, not ours.
Deletion on request
Ask and we delete - your whole organisation or a single member of staff.
Never sold
We don’t sell data, share it with brokers, or monetise it in any way beyond your subscription.
No ad tracking
No advertising pixels, no third-party trackers following your staff around the web.
An honest note from a small team
Zero is a young product in beta, built by a small team - and we would rather tell you that plainly than hide behind a wall of badges. We do not yet hold SOC 2 or ISO 27001 certification, and we won’t pretend otherwise.
What you get instead is a direct line. Security questions are answered by the people who wrote the code - not a support tier reading from a script. If something about our setup matters to your due diligence, ask us and we will show you how it works.
Diligence done? Try it properly.
See how Zero handles your team’s data first-hand. Free for 30 days - no card, no catch.