Skip to main content

Frequently Asked Questions on Zoho Security

  • Does Zoho adhere to Information Security Standards?

  • Where is my data stored? Can I choose where my account and data will be located?

  • Will Zoho employees have access to our data and what data will they have access to?

  • Is data stored on Zoho cloud products encrypted ?

  • How are encryption keys managed, and can customers upload their own keys?

  • How are passwords for Zoho cloud services stored ?

  • How is customer data segmentation implemented in Zoho cloud services?

  • How does Zoho protect itself against DDos attacks ?

  • Does Zoho conduct penetration tests and code scans ?

  • I found a vulnerability in one of your products. How do I report it ?

  • Does Zoho have an incident response program ?

  • What are Zoho's responsibilities in the event of a security incident ?

  • Is Zoho PCI DSS compliant ?

  • As a customer of Zoho, what are the additional security options I have to protect my data?

  • If a customer discontinues Zoho service, how long is their data retained ?

  • What is Zoho's business continuity and disaster recovery plan ?

  • What is your data backup policy ?

  • What controls you have in place while accessing customer data?

  • What is your availability SLA commitment ?

  • What is your risk assessment process? How often is risk assessment performed?

  • What is your employee background verification policy?

  • What certifications does Zoho possess to demonstrate its compliance with standards?

  • Will you share my data for the purpose of law enforcement?