ZapaNetworks

Security Statement

Last updated: June 16, 2026

This Security Statement summarizes how Zapa Networks approaches security across the connectivity environments it designs, installs, documents, and supports. It is written to be readable for business customers and reflects our practices and goals, not a claim of formal certification.

1. Security-First Service Delivery

Zapa treats security as part of the connectivity layer rather than a separate afterthought. Internet, Wi-Fi, firewalls, devices, cloud access, backups, and support are planned together so environments are easier to manage, document, and improve.

2. Access Control Practices

Access to customer environments follows least-privilege practices, with account-based access and role-aware permissions where practical. Administrative access is documented, and we support MFA implementation and offboarding.

3. Documentation Standards

Managed installations aim to include clear documentation — site summary, equipment list, network map, Wi-Fi and firewall records, admin access records, and service history — so your environment is auditable and not dependent on tribal knowledge.

4. Technician Partner Model

Eligible onsite work may be performed by vetted U.S. technician partners coordinated by Zapa. Technicians are licensed and insured where required, and visits are documented afterward. Availability depends on market, scope, licensing, equipment, and scheduling.

5. Backup and Resilience Planning

Zapa supports practical resilience planning, including failover connectivity, cloud and device backup coordination, and recovery planning. This is resilience planning, not a guarantee of uninterrupted uptime.

6. Security Documentation

Security documentation describing relevant practices is available on request to support customer due diligence and vendor review.

7. Compliance Readiness Roadmap

Zapa is building toward recognized frameworks, including SOC 2, ISO 27001, and CMMC readiness. These are roadmap goals and are not certification claims. Zapa will only represent certifications once they are completed and verified.

8. Incident Coordination Limits

Zapa can help coordinate incident response activities for eligible customers, including triage, provider coordination, containment support, documentation, and referrals to specialized partners where needed. Zapa is not a full incident response firm.

9. Reporting a Concern

If you believe you have found a security vulnerability or have a security concern, please contact us at security@zapanetworks.com. We review reports and respond as appropriate.

Questions about this policy? Contact Zapa Networks at legal@zapanetworks.com.