Enterprise reliability
Last updated: August 2026
When we say Zreta aims for enterprise reliability, we mean specific, published practices — not a vague slogan. This page maps that claim to what you can verify today.
Access control & auditability
- Customer portal email verification.
- Staff multi-factor authentication (TOTP + backup codes).
- Role-based access for staff and operations areas.
- Audit logging for authentication, payments, demos, and admin changes.
Data protection
- TLS in production; secure cookies; CSRF on forms.
- Passwords hashed with Django’s framework.
- Payment card data handled by gateways — not stored as raw PAN here.
- Payment proofs served only through authenticated downloads.
Backups & continuity
- Operator backup procedures for the marketing and billing platform.
- We do not invent RPO/RTO percentages on this page without a signed agreement.
- ChurchHub and CoreTrust application continuity is owned by those product deployments.
Monitoring & status
- Public system status with component probes.
- Health endpoint for operators.
- No invented historical uptime charts.
Support & incident path
- Published first-response targets on the Support SLA.
- Customer portal tickets and Support Center entry points.
- Security disclosure contact on the Security Center.
Honest limits
Roadmap products (ERP, School, Hospital, HR) are labelled as such. Product-application engines for ChurchHub and CoreTrust are external. This reliability page describes the Zreta storefront and billing platform unless stated otherwise.