Trust

Security & compliance

Security is built into how we work, not bolted on at the end. Here’s how we protect your data, your code, and your customers.

SOC 2 Type II
Aligned controls for security, availability, and confidentiality.
ISO 27001
Information security management practices throughout delivery.
GDPR
Privacy-by-design for EU and UK personal data.
HIPAA
Safeguards for protected health information in healthcare builds.

Data protection

Your data is encrypted and access is tightly controlled at every stage.

Encryption in transit (TLS 1.2+) and at rest (AES-256)
Least-privilege access with role-based controls
Regular backups with tested recovery

Secure development

Security is part of the engineering workflow, not a final gate.

Peer-reviewed code and protected branches
Automated dependency and secret scanning
Threat modelling on sensitive features

Infrastructure

We run on hardened, monitored cloud infrastructure.

Isolated environments per client
Continuous monitoring and alerting
Infrastructure-as-code, fully auditable

Access & identity

Only the right people reach your systems, and every action is traceable.

SSO and mandatory MFA for our team
Audit logs on all privileged actions
Prompt off-boarding of departing staff

Incident response

A clear, rehearsed plan for the rare event something goes wrong.

Defined severity levels and escalation
Client notification within contractual SLAs
Post-incident reviews shared with you

Vendor & data handling

We hold our subprocessors to the same bar we hold ourselves.

Vetted, contractually bound subprocessors
Data minimisation and defined retention
Secure deletion on project close

Standards we build to

We design systems to meet the regulations your industry demands — and document it so your auditors are satisfied.

SOC 2 Type IIWe operate controls aligned to the AICPA Trust Services Criteria across security, availability, and confidentiality.
ISO/IEC 27001Our information security management system follows ISO 27001 principles across people, process, and technology.
GDPR & UK GDPRWe process personal data lawfully with privacy-by-design, honouring data-subject rights and cross-border safeguards.
HIPAAFor healthcare clients we implement administrative, physical, and technical safeguards for protected health information.
PCI DSSPayment features are built to keep cardholder data out of scope wherever possible, using compliant processors.

Found a vulnerability?

We take responsible disclosure seriously. Report any security concern and our team will acknowledge it within one business day and keep you updated until it’s resolved.

security@zenlor.tech
Questions about security?