Legal
Website Security Policy
Protecting Our Platform and Users
Purpose and Scope
This Website Security Policy ("Policy") establishes the security framework, controls, and procedures for protecting the ZenVisa International website, mobile applications, APIs, and associated systems (collectively, the "Platform"), operated by Zenway International FZ-LLC.
This Policy applies to all employees, contractors, third-party service providers, and users who access or interact with the Platform. It is designed to protect the confidentiality, integrity, and availability of data and systems.
Definitions
"Breach": Any unauthorized access, disclosure, or compromise of data or systems.
"MFA": Multi-Factor Authentication: requiring two or more verification factors.
"Penetration Test": An authorized simulated cyberattack to evaluate security.
"Vulnerability": A weakness in a system that could be exploited by a threat actor.
Security Governance
ZenVisa maintains a security governance framework that includes: designation of a Security Officer responsible for oversight; security policies, standards, and procedures; regular security risk assessments; security incident reporting and response protocols; and annual security program reviews by senior management.
Data Encryption
ZenVisa implements encryption to protect data: (a) Data in transit: All data transmitted between users and the Platform is encrypted using TLS 1.2 or higher; (b) Data at rest: Sensitive data stored in databases and file systems is encrypted using AES-256; (c) Key management: Encryption keys are stored separately from encrypted data and access is restricted to authorized personnel; (d) End-to-end encryption: Client communications with consultants are encrypted end-to-end.
Access Control
Access to ZenVisa systems and data is governed by the principle of least privilege: users are granted only the minimum access necessary for their role; access rights are reviewed quarterly; privileged access requires additional approval and monitoring; and access is revoked immediately upon termination or role change.
Authentication
User authentication requirements include: strong password policies (minimum 12 characters, complexity requirements); Multi-Factor Authentication (MFA) for all administrative accounts and optional for client accounts; account lockout after 5 failed login attempts; session timeout after 30 minutes of inactivity; and secure password reset procedures with identity verification.
Network Security
ZenVisa's network security measures include: firewalls and intrusion detection/prevention systems; network segmentation to isolate sensitive systems; DDoS protection through Cloudflare; regular network vulnerability scanning; and secure VPN access for remote personnel.
Application Security
The ZenVisa Platform is developed and maintained with security best practices: secure coding standards aligned with OWASP guidelines; input validation and sanitization; output encoding to prevent XSS; parameterized queries to prevent SQL injection; CSRF protection; secure file upload handling; and security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options).
Vulnerability Management
ZenVisa maintains a vulnerability management program: automated vulnerability scanning on a weekly basis; patch management with critical patches applied within 24 hours; high-severity patches applied within 7 days; and medium-severity patches applied within 30 days. All patches are tested in a staging environment before production deployment.
Incident Response
ZenVisa maintains an incident response plan that includes: incident detection and reporting procedures; incident classification (Critical, High, Medium, Low); containment, eradication, and recovery procedures; communication protocols (internal and external); post-incident review and lessons learned; and annual incident response drills.
Business Continuity
ZenVisa maintains business continuity and disaster recovery plans: daily automated backups with 30-day retention; off-site backup storage in geographically separate locations; recovery time objective (RTO) of 4 hours for critical systems; recovery point objective (RPO) of 1 hour; and annual disaster recovery testing.
Third-Party Security
All third-party service providers with access to ZenVisa data or systems must: undergo security assessment before engagement; sign data protection and security agreements; maintain security standards equivalent to ZenVisa's; and permit security audits by ZenVisa. Third parties include: hosting providers, cloud services, payment processors, and software vendors.
User Security Obligations
Users of the Platform are responsible for: maintaining the confidentiality of their account credentials; using strong, unique passwords; enabling MFA where available; reporting suspected security incidents immediately; ensuring their devices are secure and updated; and logging out after each session. Users must not: share account credentials; attempt to bypass security controls; introduce malware to the Platform; or access data belonging to other users.
Security Monitoring
ZenVisa conducts continuous security monitoring: real-time log analysis and anomaly detection; SIEM (Security Information and Event Management) implementation; automated alerts for suspicious activities; regular review of access logs; and threat intelligence feeds for emerging risks.
Malware Protection
All ZenVisa systems run up-to-date anti-malware software with real-time scanning. Email attachments are scanned before delivery. File uploads to the Platform are scanned for malware. Users are prohibited from uploading files containing malicious code.
Secure Development
ZenVisa follows secure software development lifecycle (SSDLC) practices: security requirements in all development projects; threat modeling for new features; static and dynamic code analysis; security code reviews; and security testing before production deployment.
Cloud Security
ZenVisa uses cloud infrastructure provided by reputable vendors. Cloud security measures include: data encryption in cloud storage; secure API integrations; regular cloud security assessments; compliance with cloud provider security best practices; and monitoring of cloud access and configurations.
Mobile Application Security
The ZenVisa mobile application implements: certificate pinning; secure local storage (encrypted shared preferences/keychain); biometric authentication where available; anti-tampering measures; and secure API communication.
API Security
All ZenVisa APIs are protected by: authentication and authorization (OAuth 2.0); rate limiting to prevent abuse; input validation; HTTPS-only communication; API versioning for controlled updates; and comprehensive logging of API access.
Penetration Testing
Independent penetration testing is conducted: annually by certified security professionals; after significant platform changes; and upon discovery of new threat vectors. Penetration test findings are prioritized and remediated according to severity.
Security Training
All ZenVisa personnel receive: security awareness training upon onboarding; annual security refresher training; targeted training for personnel with access to sensitive data; and phishing simulation exercises quarterly.
Breach Notification
In the event of a security breach affecting personal data, ZenVisa will: contain and assess the breach within 24 hours of discovery; notify affected users without undue delay and within 72 hours where feasible; notify the UAE Data Protection Authority as required by PDPL; provide clear information about the nature of the breach, data affected, and steps taken; and offer appropriate remediation measures.
Compliance and Auditing
ZenVisa's security program is audited: internally on a quarterly basis; externally on an annual basis by independent auditors; and against ISO 27001, NIST Cybersecurity Framework, and UAE National Cybersecurity Strategy standards. Audit findings are reported to senior management and remediated according to established timelines.
Amendments
This Policy is reviewed every 6 months and updated as necessary to address emerging threats, technology changes, and regulatory requirements. Material changes will be posted on the website and notified to users 30 days in advance.
| Security Officer | security@zenvisa.ae |
|---|---|
| Data Protection Officer | dpo@zenvisa.ae |
| Legal Department | legal@zenvisa.ae |
| Address | RAKEZ Business Centre FZ, Ras Al Khaimah, UAE |
© 2025 Zenway International FZ-LLC (trading as ZenVisa International). All rights reserved. RAKEZ Business Centre FZ, Ras Al Khaimah, UAE.