{"slug": "zapier-security-changed-review", "title": "Zapier — security changed (review)", "summary": "Zapier updated its security page to add AI guardrails that scan AI steps, agents, and MCP connections for PII, prompt injection, and toxicity, with per-check options to block, route, or detect only. The company also added model controls letting customers approve providers or bring their own model and turn AI off entirely, agent permissions by user, team, and workspace, and encrypted app credentials stored in account-owned connections so agents and MCPs never receive raw third-party tokens. Zapier said it maintains SOC 2 Type II, SOC 3, GDPR, and CCPA compliance, with annual independent audits and penetration tests, and hosts on AWS in the United States.", "body_md": "# Zapier's security changed\n\nREMOVEDThe secure way to scale AI Don't compromise. Zapier is the only AI orchestration platform that combines the oversight IT demands with the speed your business teams need. Zapier is trusted by companies where security comes first\n\nADDEDStay in control while you scale Zapier helps you protect your data, control access, govern every AI tool and agent, and stay compliant without slowing down adoption. Security-first companies run on Zapier\n\nIdentity and Access Management Financial Services Biotech SaaS Audit Management Software Cloud Storage Industrial Technology\n\nREMOVEDEnterprise-grade security Maintain SOC 2 Type II, SOC 3, GDPR, and CCPA compliance Every execution logged, every connection tracked Query: \"All workflows touching HubSpot in 7 days\" User attribution - who, when, from where Immutable - cannot be retroactively modified Centralized access management Granular permissions Secure deployment options Complete audit trail AI Security Zapier ensures AI-driven automation is secure, transparent, and compliant, giving users full control over data and app interactions.\n\nADDEDAI security your team can trust Make security easy for everyone to uphold. Zapier applies your policies, guardrails, and audit trail across workflows, agents, and AI steps. AI guardrails : Scan AI steps, agents, and MCP connections for PII, prompt injection, and toxicity. Block, route, or detect only, per check. Model controls : Zapier lets you approve providers or bring your own model, and turn AI off entirely at any time. Agent permissions : Zapier lets you decide which apps and actions are available by user, team, and workspace. App credentials : Zapier stores encrypted app credentials (OAuth, API keys, and more) in account-owned connections, so agents and MCPs never receive raw third-party tokens. Audit trail : Zapier records every AI and agent action, so you can always see what happened and when. Infrastructure and assurance Being compliant isn't the same as being secure. Zapier does both through a robust combination of third-party testing, independent audits, and a dedicated internal security team.\n\nFeatures\n\nREMOVEDEnterprise plan governance Turn off AI apps entirely or limit to the ones you want to use Model training opt-out Automatic opt-out for Enterprise customers, and easy opt-out for all other customers Reliability With automated high availability, fault tolerance, and built-in redundancy, Zapier keeps mission-critical workflows running smoothly. Outage detection Keep your data safe when partners experience downtime Intelligent throttling Never lose data, even during peak traffic API change management Zero workflow disruptions when partner APIs evolve Data checkpoints Complete confidence your workflows will always finish Horizontal scalability Handle fluctuating workflow volume without performance degradation Data security and privacy Zapier protects sensitive data with enterprise-grade encryption, strict access controls, and compliance with GDPR, SOC 2 (Type II), and CCPA. AWS cloud security Enterprise-grade infrastructure trusted by industry leaders\n\nADDEDSOC 2 (Type II) & SOC 3 Audited annually by an independent firm. Reports available in the Trust Center. Security monitoring & incident response Real-time threat detection, with a dedicated team that owns the response. AWS cloud infrastructure Enterprise-grade hosting on AWS in the United States. Annual penetration tests Independent experts test our defenses every year.\n\nBug bounty program\n\nREMOVEDContinuous security improvement through ethical hacker insights Annual third-party penetration tests Independent verification of our robust defenses Security logging and monitoring Real-time threat detection for immediate response Custom data retention for Zaps Control exactly how long your sensitive data remains Encryption in transit to all Zapier products Your data is protected en route Encryption at rest (AES-256) to ensure safe data storage Enterprise-grade security for your stored information Governance and observability Zapier provides real-time audit logs and granular permissions for complete security oversight and control.\n\nADDEDSecurity researchers are paid to find vulnerabilities before attackers do. Built-in resilience Autoreplay and flood protection recover many failures; replay is limited and not guaranteed. Access and identity Provision, deprovision, and enforce policies all in one place. Zapier works with your existing identity and access management tools, so you can govern access from someone's first day on the job to their last.\n\nSSO (SAML)\n\nREMOVEDSeamless secure access with your existing identity provider IP allowlist Restrict access to trusted networks only\n\nADDEDSecure sign-in through your existing identity provider (IDP). Role-based access Define who can view, build, or manage, and what apps and actions they can use, set by role and workspace. Two factor authentication (2FA) Add a second layer of protection to prevent unauthorized access. SCIM provisioning Automate user provisioning for efficient access management. Allowed domains Prevent data exfiltration by locking certain apps to a company email domain (no personal accounts allowed).\n\nDomain capture\n\nREMOVEDComplete visibility and control of your organization's Zapier usage 2FA Add an essential second layer of protection to prevent unauthorized access Analytics and Zap runs API Data-driven insights to optimize your automation security Application controls Granular permissions to enforce your security policies SCIM Automate user provisioning for efficient access management\n\nADDEDRoute new signups on verified domains into your Enterprise account via SSO. Data protection and privacy Zapier protects your data in transit, at rest, and over time. Get encryption everywhere it travels or sits, retention you control, and privacy commitments you feel good about. Encryption in transit (TLS 1.2+) and at rest (AES-256) Your data is encrypted everywhere it moves and everywhere it's stored. Custom data retention Control exactly how long your sensitive data remains. Static IP Zapier's requests can come from a fixed set of IPs your firewall can allowlist. GDPR, UK GDPR, and CCPA DPA-backed processor terms included in your agreement with SCCs for international transfers. VPC Peering Connect internal data sources privately, without crossing the public internet. Audit and observability See for yourself. Zapier makes every action visible so you can search, stream, and pull into your own tools.\n\nAudit logs\n\nREMOVEDComplete visibility into user actions for compliance and security tracking Shared app connections Centralized credential management for enhanced security Security is just one layer App access controls - allowlist and blocklist Action restrictions - endpoint-level control Managed connections - company-owned credentials Domain restrictions - block personal accounts AI model policies - BYOM (Bring Your Own Model) configuration Workspace management - federated governance\n\nADDEDImmutable, searchable records of who did what, when. Asset History API Pull every change record into your own reporting tools. Log streaming Stream activity to Datadog, Splunk, or your SIEM in real time. Analytics Get an overview of your accounts so you can identify issues and drive adoption. Built for companies where every team builds Contain team info. Workspaces keep each team's work separate and scoped. Control which apps run, and what they can do. Allow or block any app, then restrict which teams or individuals can do what with it by endpoint. Lock sensitive apps to company connections. Managed connections: For designated apps, teams build only on connections you own and control. Nothing ships without signoff. Pause any changes until designated approvers say yes.\n\nFAQs\n\nREMOVEDReady to explore Zapier's security in detail? Talk to our team about your security requirements. We'll share documentation, answer technical questions, and walk you through our governance capabilities.\n\nADDEDWe're here to help Whether you need documentation, answers to technical questions, or help finishing a security review.", "url": "https://wpnews.pro/news/zapier-security-changed-review", "canonical_source": "https://isittrainingonme.com/changes/2026-10-05T14-22-17-zapier-security/", "published_at": "2026-10-05 14:22:17+00:00", "updated_at": "2026-10-05 15:19:13.083888+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "agent-protocols"], "entities": ["Zapier", "SOC 2 Type II", "SOC 3", "GDPR", "CCPA", "AWS", "MCP", "HubSpot"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/zapier-security-changed-review", "markdown": "https://wpnews.pro/news/zapier-security-changed-review.md", "text": "https://wpnews.pro/news/zapier-security-changed-review.txt", "jsonld": "https://wpnews.pro/news/zapier-security-changed-review.jsonld"}}