ZEBSOFT TRUST CENTRE
Security, Privacy and Operational Trust
Clear Commitments. Controlled Evidence. Human Accountability.
The Zebsoft Trust Centre brings together the information customers, prospects, auditors and partners need to understand how we protect information, operate our service and govern responsible technology use.
Review our public commitments, certification position and policy summaries, then request controlled evidence where information should not be published openly.

HOW TRUST IS OPERATED
Controls That Support the Service Throughout Its Lifecycle
Trust depends on connected responsibilities and evidence—not one certificate or a collection of claims. Zebsoft applies governance across people, technology, suppliers, service operation and improvement.
FROM COMMITMENT TO ASSURANCE
Policy → Owned Control → Operation → Evidence → Human Review → Improvement
A published commitment only creates trust when responsibilities are defined, controls are operated, evidence is retained and competent people review the outcome.
ASSURANCE AT A GLANCE
The Foundations of Trust in Zebsoft
These statements provide a concise overview. Certification, testing and detailed evidence remain subject to their defined scope, validity and appropriate disclosure controls.
PUBLIC POLICY CENTRE
Review Zebsoft Policy Commitments
Open a concise public statement without leaving the Trust Centre. Controlled policies and supporting evidence remain available through the appropriate request and disclosure route.
PUBLIC INFORMATION AND CONTROLLED EVIDENCE
Share What Builds Trust. Protect What Could Create Risk.
The Trust Centre is designed for useful transparency. Some documents can be published openly; others require a legitimate business purpose, identity checks, confidentiality terms or an established customer relationship.
RESPONSIBLE AI
AI Can Assist the Work. It Does Not Own the Decision.
Where approved AI capability is used, it may help interrogate authorised information, generate summaries or support content through defined prompts. Customers can determine whether optional AI functionality is appropriate for their environment.
AI does not become the control owner, approve evidence, interpret legal duties, accept risk or make assurance decisions. Competent people remain responsible for the source information, prompt, review, decision and resulting action.
Customer information is not presented as training material for public models. The applicable service configuration, processing role, contractual position and supplier arrangements remain subject to the agreed customer scope.
PRACTICAL QUESTIONS
Zebsoft Trust Centre FAQs
These answers describe the general Trust Centre route. Customer-specific commitments remain governed by the applicable proposal, contract, data-processing terms and agreed service configuration.
What is the Zebsoft Trust Centre?
It is the central public route for understanding Zebsoft security, privacy, resilience, responsible-AI and corporate commitments, together with the evidence-request process.
Does ISO/IEC 27001 certification cover every customer obligation?
No. Certification applies to the management system and scope stated on the certificate. Customers must still assess their own requirements, configuration, use and contractual obligations.
Where is the platform hosted?
The Zebsoft cloud platform is hosted in AWS London. Any customer-specific architecture or additional service arrangement should be confirmed through the agreed scope.
Can we receive a security questionnaire?
Yes. Provide the questionnaire, purpose, deadline and relevant opportunity or customer relationship. Zebsoft will determine the appropriate response and evidence route.
Are penetration-test reports public?
Detailed reports are not published openly. Relevant evidence may be shared through a controlled process depending on sensitivity, purpose, customer status and confidentiality arrangements.
Does Zebsoft use customer data to train public AI models?
Zebsoft does not present customer information as training material for public models. Optional AI use remains governed by the applicable service configuration and processing arrangements.
How do we report a suspected vulnerability?
Use the security contact route and provide sufficient detail for safe investigation. Do not publicly disclose or exploit a suspected vulnerability while Zebsoft assesses it.
How current is the information?
Trust Centre content is reviewed periodically and when relevant changes occur. Certificates, reports and contractual evidence should always be checked for their individual version, scope and validity.

