Security and Data Handling
Zest is SOC 2 Type II certified. The certification covers our security, data handling, and confidentiality controls, and is independently audited on an ongoing basis.
Payment Data
Zest does not store, process, or transmit credit card data. All payments flow through your connected PCI DSS Level 1 payment processor (Stripe or Adyen), which handles cardholder data directly. Card data never touches Zest's systems.
Web Accessibility
Zest targets WCAG 2.1 Level AA across our storefronts and gifting experiences. We use automated accessibility scanning to identify issues across our applications, and we remediate identified issues proactively as part of our standard release cycle.
Trust Center
For a closer look at our security posture, we can share access to our Vanta Trust Center under NDA. Email [email protected] to request access.
