ZX-C02 - Security & data

What happens to your data.

Zenion holds employee records and payroll. Zenmart holds orders and customers. A page of adjectives would be the wrong answer to that responsibility, so here is what we actually do, and one thing we deliberately do not claim.

01

Practices

On every change, not once a year.

01

Review on every change

Code and security review before anything merges, and the tests run on every commit.

02

Least privilege

Role-based access on the platforms, with granular permissions behind every admin action.

03

Audit trail

Every change to a record on Zenion and Zenmart is logged: who, what, when.

04

Encrypted transport

TLS on everything public-facing, enforced, not optional.

05

Data portability

Your data on our platforms is exportable in full, at any time, in usable formats.

06

Handover on services

Build engagements end with code, infrastructure and credentials handed over documented, and our access removed on request.

02

The claim we do not make

Aligned is not certified.

The why page says SOC 2-aligned, and aligned is the whole claim: we run our engineering to the framework's controls, and we have not sat a SOC 2 audit. If your procurement needs the certificate, ask us early and you will get a plain answer about where we stand.

03

Reporting

Found something?

Security reports go to [email protected]. We read them first and reply within 48 hours.

Start a project

Tell us where you're stuck.

We'll come back with a plan, a timeline and a fixed first step - not a deck. If we're the wrong fit we'll say so, and say who isn't.

What happens next

  1. 01

    You send the problem

    A paragraph is enough. No brief required.

  2. 02

    We come back in 48h

    With questions, or with a scope and a number.

  3. 03

    One call, one engineer

    You talk to whoever would build it, not a salesperson.