Home/Security & trust

We touch your code, your environments and your evidence. Here is exactly how.

A QA partner sees more of your system than most vendors: source, staging, test data, screen recordings of every failure. This page sets out what we access, where it lives, how long we keep it, the standards we benchmark our controls against, and what we hand your security team for their review.

Questionnaires (SIG Lite, CAIQ, or your own) returned within five business days.

Principles

Four rules every engagement runs on.

01

Least access, named people

Only the named engineers on your engagement get access, only to the repositories and environments in scope, through your identity provider where possible. Access is revoked within 24 hours of a role change.

02

Your environment first

Tests run in your pipeline and against your staging by default. Production is touched only with written authorisation, on read-only or synthetic paths, with test payment methods.

03

Evidence is personal data until proven otherwise

Videos, traces and HAR files can capture screen content. We treat them as confidential, store them encrypted, keep them for 90 days by default, and delete on request.

04

Nothing without authorisation

Load rehearsals, production runs and any change to scope are agreed in writing, scheduled with your platform lead, and logged.

Data handling

What we access, where it lives, how long we keep it.

DataWhat it isWhere it livesRetentionWho can access
Source codeRead access to the repositories in scope; generated tests submitted as pull requestsYour source-control provider. No long-lived clones outside CI runners.Nothing retained after a run completesNamed engineers on your engagement; revocable by you at any time
Environments & secretsStaging URLs, test accounts, CI secretsYour vault or CI secret store. We never store customer credentials in plain text or in tickets.Deleted at engagement end; rotated on requestNamed engineers; access reviewed quarterly
Test evidenceVideos, Playwright traces, HAR files, console logs for failuresEncrypted storage in the region agreed in your SOW, or your own storage if you prefer90 days by default; configurable; deleted on requestYour team and your named engineers; access logged
Load-test dataSynthetic users, synthetic orders, test payment methodsGenerated for the rehearsal; runs scheduled to avoid real usersAggregated results kept with the report; raw runs purged after 30 daysYour platform lead and your named engineers
Reports & verdictsCoverage maps, go/no-go verdicts, trend reportsDelivered to you; a copy retained for the engagement recordDuration of the engagement plus 12 months, unless you ask for earlier deletionYour stakeholders; your named engineers
Business contactsNames, work emails, roles of the people we work withOur business systemsPer the Privacy PolicyEngagement and account staff

Production personal data is never copied into test systems. Where a test must use production-like data, we use synthetic or pseudonymised datasets agreed with you.

Controls

Operational and technical controls, by domain.

Identity & access
  • Multi-factor authentication on every system that touches customer data
  • Named accounts only — no shared logins; least privilege by engagement
  • Quarterly access reviews; offboarding within 24 hours
Encryption
  • TLS 1.2+ for all data in transit
  • Encryption at rest for hosted evidence and reports
  • Keys managed by the cloud provider's key service; customer-managed keys on request
Secure development
  • Peer review on every change to the platform; dependency and secrets scanning in CI
  • Platform tested against the OWASP Top 10; OWASP ASVS Level 2 as the target
  • Customer-led penetration tests of the platform welcomed with notice
Vulnerability management
  • Patching targets: critical within 7 days, high within 30 days
  • Hosts and containers hardened against CIS Benchmarks
  • Responsible-disclosure channel below
Incident response
  • Documented incident process with a named owner
  • Customers notified within 48 hours of confirming an incident affecting their data — inside GDPR's 72-hour and India DPDP's "without delay" windows
  • Post-incident report with root cause and corrective actions
People & continuity
  • Every engineer under written confidentiality obligations; security training at onboarding and annually
  • Background verification where local law permits
  • Backed-up engagement records; documented continuity plan for peak-day standby

Security benchmarking

The standards we measure ourselves against.

We map our controls to the frameworks your security team already uses, and hand you the mapping rather than a badge. Where we are working towards a certification, we say so plainly.

  • ISO/IEC 27001:2022 — Annex A control mapping available on request; certification on the roadmap.
  • SOC 2 Trust Services Criteria — security, availability and confidentiality criteria mapped; Type II report on the roadmap.
  • OWASP ASVS Level 2 and OWASP Top 10 — for the Zenius platform itself.
  • CIS Benchmarks — hardening baseline for hosts and containers.
  • NIST Cybersecurity Framework 2.0 — programme structure: identify, protect, detect, respond, recover.
  • GDPR, UK GDPR, CCPA/CPRA, India DPDP Act 2023 — see the Privacy Policy and DPA.
  • WCAG 2.2 AA — accessibility target for this site and the platform UI.

For your review

What we hand your security and legal teams.

Within 5 business days

Your questionnaire, completed

SIG Lite, CAIQ, or your own format, answered by the people who run the controls — not a sales deck.

With the contract

DPA, SCCs, control mapping

Data Processing Addendum with EU Standard Contractual Clauses and the UK Addendum, the sub-processor list, and the ISO 27001 / SOC 2 control mapping.

On request, under NDA

Architecture, data flows, test results

Data-flow diagram for your engagement, platform architecture, and penetration-test summaries as they are completed. Annual right to audit in the MSA.

Responsible disclosure. Found a vulnerability in the Zenius platform or this website? Email rahul@zenius.ai with "Security" in the subject. We acknowledge within two business days, keep you informed, and will not pursue good-faith researchers who respect user privacy and give us reasonable time to fix.