ZMANDA TRUST CENTER

Security and compliance
enterprises can trust

Zmanda protects critical data for enterprises across healthcare, finance, and government. Our security
practices are independently audited, compliance is certified, and documentation is ready for your review.

Schedule a security review Enterprise Trust | Zmanda

Certified to meet global standards

Zmanda is a BETSOL product. BETSOL’s compliance program is designed to meet the requirements of regulated industries. Each certification below represents an ongoing commitment to customer data protection.

All certifications are audited annually by QRC, an accredited third-party assessor.

SOC 2 Type II
BETSOL's SOC 2 Type II attestation verifies the operational effectiveness of our security controls over a continuous 12-month period. The audit evaluates our systems against the trust principles of security, availability, and confidentiality—ensuring your data is protected, accessible when needed, and handled with care.

ISO 27001
BETSOL maintains ISO 27001 certification for our information security management system. This globally recognized standard validates our systematic approach to managing sensitive information through risk assessment, security controls, and continuous improvement.

ISO 9001
Our ISO 9001 certification demonstrates BETSOL's commitment to consistent quality across product development, customer support, and service delivery. This standard ensures our processes are designed to meet customer requirements and drive continuous improvement.

HIPAA
Zmanda Pro supports HIPAA-regulated environments by providing AES-256 encryption for data at rest and in transit, role-based access controls, immutable backups, and detailed audit logging to safeguard sensitive healthcare data. Zmanda also executes business associate agreements (BAAs) with healthcare customers to support HIPAA-compliant backup and recovery environments.

PCI DSS
BETSOL maintains PCI DSS compliance to support customers handling payment card data. Our security controls including AES-256 encryption, role-based access control, and comprehensive audit logging meet the requirements for protecting cardholder data in backup and recovery environments.

How Zmanda Pro protects your data

Here's how Zmanda Pro protects your data at every layer.

Data encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3, meeting HIPAA and PCI DSS encryption requirements.
For: Healthcare, finance, and any organization handling sensitive customer data.

Immutable backups

Time-locked backups that cannot be modified or deleted even by administrators until retention periods expire, providing verified ransomware protection.
For: Organizations concerned about ransomware or insider threats.

Bring your own encryption keys (BYOK)

Maintain complete control over your encryption keys with zero-knowledge architecture, ensuring Zmanda never has access to your unencrypted data.
For: Enterprises with strict data sovereignty or zero-trust requirements.

Air-gapped backup support

Fully offline, self-hosted deployments that require no internet connectivity for organizations requiring physical isolation from network-based threats.
For: Government agencies, defense contractors, and critical infrastructure.

Role-based access control (RBAC)

Granular permissions ensure users access only what they need, with full audit logging exportable to your SIEM.
For: Teams needing audit trails for compliance or internal security policies.

Flexible data residency

Choose Zmanda-managed cloud (US, EU, APAC regions), connect your own S3-compatible storage, or deploy fully on-premises—your data stays where you need it.
For: Multinational organizations or those bound by GDPR, data localization laws, or internal policies.

Documentation for your security review

Access security documentation and legal agreements for your vendor assessment.

Product Security

Resource Status
Encryption & key management View
Security whitepaper View
Architecture diagram View

Guides & Templates

Resource Status
Disaster recovery plan template View
BCDR planning guide View

Legal

Resource Status
HIPAA View
Privacy policy View
Terms of service View
Cookie policy View

Why security teams trust Zmanda Pro

Years of enterprise
data resilience

Up to

TCO savings

Industry average Net
Promoter Score

What our clients say

“46% cost reduction
with Zmanda”

No more surprise costs. Zmanda's pricing is transparent - we know exactly what we'll pay next year. Plus, no mandatory training, no overhead!

Sr. DB Advisory

Financial Services

Big cost reduction
with Zmanda”

No more surprise costs. Zmanda's pricing is transparent - we know exactly what we'll pay next year. Plus, no overhead!

Sr. Manager

Data center solutions

“Helps me be
efficient in my role”

Zmanda's monitoring alerts, reporting, and third-party integrations have boosted my efficiency. The support team is responsive and reliable, ensuring our security and compliance needs are met.

Sr. DB Advisory

Financial Services

“Zmanda’s software
and customer support
has been great

Zmanda has spent time helping with any bugs, explaining errors, and adding necessary features so we can continue to transition from our old backup software to Zmanda Enterprise.

Their effort has helped to keep our backups rolling!

Systems Programmer

Researchgate

“Good software,
impeccable support
experience”

Zmanda’s support is outstanding and the software is incredibly easy to use. It works reliably with exceptional flexibility. We’re able to use it across all our different setups.

Chief Executive Officer

Computer & Network Security

Ready to schedule
your security review?

Our team is here to answer your questions, walk you through our compliance documentation, and help you complete your vendor assessment.

FAQs

Zmanda Pro protects backup data using AES-256 encryption for data at rest and TLS encryption for data in transit. Backup data is automatically encrypted, compressed, and deduplicated before leaving your environment, helping ensure sensitive information remains secure throughout the backup and recovery process.

Yes, Zmanda supports bring-your-own-key (BYOK) functionality, giving you complete control over your encryption keys. This ensures that only your organization has access to decrypt your backup data. Learn more at Encryption & Key Management | Zmanda Docs .

Zmanda Pro ensures enterprise security and compliance by supporting deployments that meet regulatory requirements such as GDPR, HIPAA, and SOC 2. Our security architecture, encryption, access controls, and audit logging capabilities help organizations implement backup and recovery environments that align with these compliance frameworks.

You have complete control over where your data is stored. Choose Zmanda Cloud Storage, connect your own S3-compatible storage, or keep backups fully on-premises. You can also back up to multiple storage targets to achieve the 3-2-1-1-0 rule for maximum data resilience.

Yes, Zmanda Pro supports immutable backup storage options that prevent backup data from being encrypted, modified, or deleted by ransomware or malicious actors, providing an additional layer of protection for your critical data.

Zmanda Pro includes role-based access control (RBAC), multi-factor authentication (MFA), detailed audit logging, and secure API access controls to ensure only authorized personnel can access your backup infrastructure.

Zmanda implements zero-knowledge encryption architecture, meaning your data is encrypted before it leaves your environment. Combined with granular access controls and comprehensive audit trails, you maintain complete visibility and control over who can access your backup data.

Got a question that you need an answer to asap?

Call Us

Write to Us

💬