Security at SZG Labs

Effective Date: September 1, 2026

At SZG Labs, security and architectural integrity are fundamental to everything we build. Whether designing autonomous Agentic AI workflows, executing mission-critical Odoo ERP migrations, or deploying cloud data pipelines, we apply enterprise-grade defense-in-depth controls to protect intellectual property, financial data, and system availability.

1. Cloud Infrastructure & Hosting Security

Our client environments and internal production architectures are hosted across industry-leading cloud providers, primarily Amazon Web Services (AWS) and Google Cloud Platform (GCP):

  • Network Isolation: Dedicated Virtual Private Clouds (VPCs), strict security groups, and ingress/egress network access control lists (NACLs).
  • High Availability: Multi-Availability Zone (Multi-AZ) architecture with automated failover and geo-redundant storage.
  • DDoS Mitigation: Cloud-native edge protection, automated rate limiting, and web application firewalls (WAF).

2. Cryptography & Data Protection

  • Encryption in Transit: All web, API, and administrative communications enforce TLS 1.2 or TLS 1.3 with modern, high-strength cipher suites. Secure protocol standards (SFTP, AS2, HTTPS) are enforced for EDI and ERP data exchanges.
  • Encryption at Rest: All databases, disk volumes, snapshot backups, and storage buckets enforce AES-256 encryption.
  • Key Management: Cryptographic keys are managed via AWS Key Management Service (KMS) or Google Cloud KMS with automated key rotation and strict IAM separation.

3. AI & Large Language Model (LLM) Governance

For organizations deploying Agentic AI and automated workflows, data sovereignty is paramount:

  • Zero Model Training: All enterprise AI integrations utilize commercial API agreements that legally prohibit foundation model providers from training or fine-tuning models on client prompts or data.
  • Ephemeral Processing: AI agent middleware operates on transient data structures. Data is processed in-memory during execution and is never stored on model servers.
  • Prompt & Data Sanitization: Automated sanitization layers scrub sensitive PII and secrets before payload transmission to inference endpoints.

4. Financial & Payment Processing Security

All client invoicing, cardholder transactions, and ACH payments are handled through Zoho Payments and certified Level 1 PCI-DSS compliant payment gateways. SZG Labs never stores, processes, or transmits raw credit card numbers or banking passwords on our servers. All billing data is tokenized and processed through secure, encrypted vaults.

5. Engineering Operations & DevOps Hygiene

  • Infrastructure as Code (IaC): Environments are provisioned and versioned using Terraform, ensuring auditable, repeatable, and peer-reviewed infrastructure changes.
  • Principle of Least Privilege (PoLP): Role-based access control (RBAC) and just-in-time access scoping for all administrative roles and IAM service accounts.
  • Multi-Factor Authentication (MFA): Hardware-backed security keys or TOTP multi-factor authentication are mandatory across all company accounts, code repositories, and cloud consoles.
  • Endpoint Protection: Engineering workstations require full-disk encryption (FileVault / BitLocker), auto-locking, and automated security patch management.

6. Compliance & Data Processing Agreements (DPA)

We provide enterprise-ready Data Processing Addenda (DPAs) incorporating Standard Contractual Clauses (SCCs) to support our clients' compliance requirements under GDPR, CCPA, and industry data protection frameworks.

7. Vulnerability Disclosure & Security Contact

If you identify a potential security issue or have questions regarding our security controls, please contact our security team immediately at [email protected].