Menu

Security

Kept carefully, and checkably.

The whole point of Zest is treating guest data properly — so here, plainly, is how the platform itself is kept: where your data lives, who can reach it, and what you can check for yourself. If a question isn't answered below, ask it.

UK-hosted on Microsoft Azure

Each customer's data kept separate

Support access time-limited & logged

Fails open — guests stay online

Version 1.0 · 11 July 2026 · Covers the Zest Wi-Fi platform

No. 01

Where your data lives

In the UK, on Microsoft Azure — that's where the guest records your venues collect are hosted.

Each customer's data is kept separate at the database level. Your venues' records don't sit in one shared pot with everyone else's — the separation is structural, not a filter someone has to remember to apply.

No. 02

Who can touch it

Access follows the job. Team roles carry per-site permissions — a manager runs their own venue without seeing the rest of the group — and two-factor authentication is required wherever guest data is touched.

That includes us. When Netmo support ever needs to look inside your account, the access is designed to be checkable rather than taken on trust: it's time-limited, every action is logged, destructive actions are blocked outright, and the complete history is visible to you.

No. 03

How it's built

The platform's secrets are kept in a managed vault. Anything uploaded through the portal designer — logos, background photos — is re-processed before it's ever served, so what reaches a guest's phone is a clean image, whatever arrived.

And the portal fails open, by design: if Zest is ever unreachable, your guests still get online. A problem with our platform should never become a problem with your Wi-Fi.

No. 04

The records themselves

Consent records are the part venues rely on, so they're kept the most carefully. The wording each guest agreed to is versioned and every record is timestamped; the marketing opt-in is always its own tick; retention windows run per venue, and every deletion is noted in the log.

The records are tamper-evident — designed to be only ever added to, never quietly edited, by your team or by ours. If a question ever comes, the answer is a lookup, not a reconstruction.

No. 05

This website

The site you're reading is mostly static files. Cloudflare Web Analytics counts visits and measures page speed without cookies or advertising trackers; it doesn't give us a profile of individual readers. The contact form also loads Cloudflare Turnstile so that real enquiries aren't buried under spam. The privacy notice sets out exactly what each service sees, and what it doesn't.

No. 06

Questions & reports

A security question before you sign up, or something you think we should know about? Email hello@netmo.it — it lands with the people who built the platform, and we reply within one working day.

The same address is published at /.well-known/security.txt, where security researchers and their tools expect to find it. If you believe you've found a problem, we'd much rather hear about it than not.

End of overview · Version 1.0 · 11 July 2026