Article
Published on October 7th, 2026 by James
Zynk connects business systems like Sage, Shopify, Salesforce, Magento, and dozens of others through workflows we build and manage. Every day, our platform moves customer orders, invoices, stock levels and financial records between the systems our customers depend on to trade.
As an IPaaS, our role extends beyond managing our own systems. Every connection we enable creates opportunities for customers to work more efficiently, but it also creates responsibilities. That's why security has to be embedded into everything we do, and why we've adopted the UK government's Software Security Code of Practice, published by the Department for Science, Innovation and Technology (DCMS) and the National Cyber Security Centre (NCSC).
Most software sits inside one organisation's perimeter. An integration platform sits between several. Every connector we build is a bridge between one customer's finance system, another customer's e-commerce platform, and the CRM tying it all together.
That position carries real weight. A weakness in an integration layer doesn't just expose one system; it can expose everything connected to it. Recent supply chain incidents affecting well-known UK retailers and service providers have shown how disruption rarely stays contained to the organisation it started with; it travels through the connections between systems and suppliers.
For a platform built on connecting systems, managing that risk effectively isn't an annual checkpoint. It's a daily discipline focused on building a security-conscious organisation and software that our customers trust us to handle on their behalf, particularly those without dedicated in-house security teams.
The Code of Practice is a voluntary framework covering 14 principles across four themes: secure design and development, build environment security, secure deployment and maintenance, and communication with customers about security posture.
It isn't a box-ticking exercise. It's built around continuous improvement rather than a one-off audit, requiring organisations to demonstrate how security is practised day to day, rather than simply having a policy document stored on a shared drive.
We wanted a framework that would help us continually strengthen our software security and clearly demonstrate that commitment to our customers.
The Code gave us a recognised, government-backed framework that aligned closely with the values we already held: that security is foundational to trust, not a feature layered on afterwards. Adopting it formally lets us validate our existing practices, sharpen the areas that needed it, and communicate our commitment more clearly to customers and partners.
It reflects the kind of organisation we strive to be, and one we want to help build across our industry:
A trusted integration provider
An organisation committed to continuous improvement
A proactive advocate of secure software development
A partner helping raise security standards across the wider ecosystem
When a customer connects Zynk to their Sage, Salesforce or Shopify account, they grant access to core business data, including sales orders, customer records, invoices, and potentially payment or banking information. If that access were ever compromised, the impact wouldn't stop with Zynk; it would directly affect our customers' operations. Treating this responsibility with the seriousness is fundamental to everything we do.
As a ... organisation, we understand that this does not end at our own perimeter. Unlike a traditional supply chain, we're not sourcing components from a long line of vendors, but we do sit permanently between our customers and the platforms we connect them to. That means part of managing risk responsibly is understanding the security standards those partner platforms hold themselves to: how they handle authentication, how data moves through their APIs, and how seriously they take the same questions we're asking of ourselves. We view security as a shared responsibility across the entire integration ecosystem, which is why we place immense value on key partners like Sage, who actively champion and drive those same high standards across their own networks.
Strengthening an Established Security Programme
Zynk already holds ISO 27001 certification, and the Code complements that in a practical way. ISO 27001 focuses on the management system, covering risk assessment, governance, and the continuous improvement of our information security controls. The DCMS Code focuses specifically on the software itself: secure coding practices, vulnerability handling, and transparent security communication with customers. Working with both frameworks gives us a clearer picture of our strengths and areas for improvement, while giving customers additional reassurance alongside our ISO certification.
Sage, one of our longest-standing platform partners and itself a signatory to the DCMS Software Security Ambassador Scheme under the Cyber Resilience Compliance Pledge, is championing wider adoption of the Code across its partner ecosystem. We wanted to stand alongside that effort, not simply respond to it. helps establish a consistent, recognised standard across Sage's platform and the wider connected ecosystem.
A growing number of the businesses we work with, and the accountants and consultants who refer them to us, are asking more pointed questions about how their data is handled once it leaves their own system boundary. Being able to point to alignment with a recognised government code of practice, alongside ISO 27001, gives them a clear and credible answer.
Adopting the Code has reinforced a few things we already held ourselves to, and sharpened others:
Security built into the design of new connectors and workflows from the outset, rather than reviewed only once something is close to release
Clear, documented processes for identifying and handling vulnerabilities as they arise
Greater transparency with customers about our security posture and how their data is handled across integrations, not just at the point of sale, but throughout the life of the account
None of this replaces ISO 27001. It sits alongside it, giving us a software-specific lens on top of the management system view, and giving customers confidence that the two are working together rather than existing as separate compliance exercises.
We've completed our initial review against the 14 principles and are refining a few areas where our documentation and internal processes can be strengthened. As with ISO 27001, this isn't a certificate to earn once and file away; it's a standard we intend to continuously measure ourselves against as Zynk grows and as our connectors and customer base expand.
If you're a Zynk customer and want to learn more about how we handle security across your integrations, feel free to contact your account manager. And if you're evaluating integration partners, make sure security is on your checklist, and ask us how we handle it. Security and resilience can't be treated as annual checkpoints; they are ongoing commitments that help our customers engage with confidence.
Zynk connects your eCommerce platforms, Accounting software, ERP systems, CRMs, Databases, and marketplaces—all in one seamless solution. Simplify your processes, save time, and focus on growing your business.
Get in Touch