Zanda protects your practice’s data with layered security controls. This article covers three of them: encryption that protects the data itself, tightly controlled and logged access by Zanda staff, and account-level protections against unauthorized logins.
How data is encrypted
All customer data is encrypted both at rest (while stored on disk or in the database) and in transit (moving between the database and web servers, and between those servers and a customer’s browser). Even someone with direct administrative access to the underlying storage cannot read a stored file without the corresponding decryption key.
For highly sensitive information, such as clinical notes and forms, each practice has its own unique encryption key, so different practices’ data is never protected by the same key.
Keys themselves are managed through an established, enterprise-grade, auditable key-management service, encrypted, and never stored in the database alongside the data they protect. When the application needs to save or read information, it retrieves and uses the relevant key securely. This means a database backup or restore on its own cannot expose the underlying information, since the key material is required separately.
When Zanda staff can access account data
A Zanda team member only ever signs into your account to provide support, after you have raised an issue and given us permission to access it. We always ask first - it is never automatic, and never without your knowledge.
Everyone with potential access has passed a police check before ever being granted it, completed privacy and information-security training, and signs in using their own two-factor authentication, never yours. A team member typically sees the account the way the assisted user sees it, and where an issue genuinely calls for more, access stays limited to what that specific request needs. Every session is logged in a write-only record that cannot be edited after the fact, capturing who accessed the account, when, and what actions were taken - though not in the same Log File a practice can view directly. See Zanda Staff Access to Your Account and Client Data for the full detail on when and how this happens, and how to request confirmation of any access to an account.
Protecting your account from unauthorized login attempts
Zanda enforces password length and complexity rules, and repeated unsuccessful login attempts trigger a temporary lockout - see Logging into Your Account for what that looks like in practice. If a locked-out user needs back in sooner, a practice admin can reset that lockout directly from Account Settings > Practice > Users, without needing to contact Zanda support or wait it out.
Two-factor authentication adds a second login step beyond email and password, and can be turned on per user: an admin can require it for an individual team member, and the Master User manages their own. See Activating Two Factor Authentication for how to set it up.
Sessions also log out automatically after a period of inactivity, on a fixed timeout that isn’t adjustable per practice. For anyone stepping away from a shared or unattended device, even briefly, a password-protected screen lock is worth using on top of that.
A few things a practice can do to strengthen its own login security: give each team member their own user account rather than sharing a login, require two-factor authentication for the individual users who need it, and use a password-protected screen lock or device lock whenever a device is left unattended.
Frequently Asked Questions
What does encryption protect, and could a backup be read on its own?
Customer data, both while it’s stored and while it’s moving between the database, the web servers, and a customer’s browser. A backup can’t be read on its own either - the corresponding decryption key is required separately, and that key isn’t stored in the database alongside the data it protects.
Why might Zanda support need to access my account?
To provide effective support or investigate a technical issue - always with permission, never automatic, and limited to the information the specific request needs.
Can I see when a Zanda staff member accessed my account?
Not directly through your own Log File - support sessions aren’t included there. Contact Zanda Support with the date range and reason for your request, and the team can confirm. See Zanda Staff Access to Your Account and Client Data for more.
What happens if I get locked out after too many failed login attempts?
Your account is temporarily locked - see Logging into Your Account for the specific lockout period. A practice admin can also reset the lockout directly from Setup Menu > Users at any time, so there’s no need to contact Zanda support or wait it out.
What can a practice do to strengthen its own login security?
Give each team member their own user account instead of sharing a login, require two-factor authentication for the individual users who need it, and use a password-protected screen lock or device lock whenever a device is left unattended. See Activating Two Factor Authentication for setup steps.
