End-to-end encryption

All data in transit uses TLS 1.3. Sensitive data at rest is encrypted with AES-256. Submission images are encrypted from capture through delivery.

Learn more →

Identity verification

Every Zoomer completes KYC before first payout. Government ID + liveness check. Verified by our own regulated KYC system, not stored by quiXzoom.

Learn more →

Data residency

All data stored in EU (Stockholm, eu-north-1). No third-country transfers. GDPR compliant by design. SOC 2 Type II in progress.

Learn more →

AI review & fraud detection

Every submission passes automated quality and location verification. Anomaly detection flags suspicious patterns. Human review for edge cases.

Learn more →

Compliance & Certifications

GDPR Compliant EU Data Residency SOC 2 In Progress ISO 27001 Roadmap

quiXzoom is built for regulated industries. We maintain a comprehensive compliance programme covering data protection, payment regulation (PSD2), and anti-money laundering (AML) requirements. Our KYC and payment processors are fully regulated entities under EU law.

Responsible Disclosure

We take security seriously and welcome responsible disclosure of vulnerabilities. If you discover a security issue, please report it to:

Please include sufficient detail to reproduce the issue, and allow reasonable time for remediation before public disclosure.

Data Processing

quiXzoom acts as data controller under GDPR. Key processors:

All processor relationships are governed by Data Processing Agreements compliant with GDPR Article 28.

Questions about security?

Our security team is available for enterprise customers and researchers.

Contact Security Team →