ZEBSOFT TRUST CENTRE

Security, Privacy and Operational Trust

Clear Commitments. Controlled Evidence. Human Accountability.

The Zebsoft Trust Centre brings together the information customers, prospects, auditors and partners need to understand how we protect information, operate our service and govern responsible technology use.

Review our public commitments, certification position and policy summaries, then request controlled evidence where information should not be published openly.

  • Security and privacy information in one accessible place
  • Public assurance separated from sensitive evidence
  • Policy summaries with clear ownership and review routes
Zebsoft Trust Centre security privacy and assurance image placeholder

HOW TRUST IS OPERATED

Controls That Support the Service Throughout Its Lifecycle

Trust depends on connected responsibilities and evidence—not one certificate or a collection of claims. Zebsoft applies governance across people, technology, suppliers, service operation and improvement.

Identity and Access

Role-based permissions, native multi-factor authentication and supported Microsoft OIDC connections help organisations control who can access the service and what they can do.

Infrastructure and Data

Defined hosting, backup, recovery, environment and administrative controls support the confidentiality, integrity and availability of the platform and customer information.

Secure Development

Development, change, testing and release activities are governed through defined responsibilities, segregated access and controlled deployment practices appropriate to the service.

Incident Response

Security and service incidents are assessed, assigned and managed through defined response and communication routes, with lessons feeding corrective action and improvement.

Supplier Governance

Relevant suppliers and subprocessors are evaluated and governed according to the services they provide, associated risk and applicable contractual or data-protection requirements.

People and Responsibility

Competent people retain responsibility for security, privacy, service, risk and AI decisions. Technology may support analysis but does not assume accountability.

FROM COMMITMENT TO ASSURANCE

Policy → Owned Control → Operation → Evidence → Human Review → Improvement

A published commitment only creates trust when responsibilities are defined, controls are operated, evidence is retained and competent people review the outcome.

ASSURANCE AT A GLANCE

The Foundations of Trust in Zebsoft

These statements provide a concise overview. Certification, testing and detailed evidence remain subject to their defined scope, validity and appropriate disclosure controls.

ISO/IEC 27001 Certified

Zebsoft operates a certified information security management system within the scope stated on its current certificate.

UK-Hosted Service

The Zebsoft platform is cloud-hosted in AWS London, supported by defined backup, access and service-management controls.

Independent Security Testing

Independent penetration testing supports the evaluation of technical security. Detailed results are controlled rather than published openly.

UK G-Cloud Supplier

Zebsoft is available through the UK government cloud procurement framework for eligible public-sector purchasing routes.

PUBLIC POLICY CENTRE

Review Zebsoft Policy Commitments

Open a concise public statement without leaving the Trust Centre. Controlled policies and supporting evidence remain available through the appropriate request and disclosure route.

Information Security

How Zebsoft protects information through governance, risk management, access control and continual improvement.

Data Protection and Privacy

How personal information is handled lawfully, transparently and proportionately across our business and service relationships.

Responsible AI Use

How approved AI tools may support work while responsibility, judgement, approval and assurance remain human.

Acceptable Use

The responsible-use expectations applying to people, accounts, devices, information and services used for Zebsoft business.

Business Continuity and Recovery

How Zebsoft prepares for disruption, protects priority activities and supports proportionate service recovery.

Security Incident Response

How suspected security events are reported, assessed, contained, communicated and followed through to improvement.

Supplier and Subprocessor Governance

How external services are evaluated and controlled in proportion to access, dependency, information and service risk.

Vulnerability Disclosure

How security researchers and other parties can report a suspected technical vulnerability responsibly and confidentially.

Accessibility

Our commitment to improving access to Zebsoft information and platform experiences through proportionate, continuing work.

Environmental Responsibility

How Zebsoft considers environmental impacts, resource use, purchasing and improvement within its scale and influence.

Ethical Business and Modern Slavery

Our expectations for lawful, fair and responsible conduct within Zebsoft and relevant supply relationships.

Quality and Customer Commitment

How Zebsoft approaches service quality, customer communication, controlled change, corrective action and improvement.

PUBLIC INFORMATION AND CONTROLLED EVIDENCE

Share What Builds Trust. Protect What Could Create Risk.

The Trust Centre is designed for useful transparency. Some documents can be published openly; others require a legitimate business purpose, identity checks, confidentiality terms or an established customer relationship.

Publicly Available

Public policy statements, certification summaries, hosting information, responsible-AI commitments, privacy information, accessibility position and security contact routes.

Where a complete public document is published, the stable page or document link should remain available for bookmarking, printing and due-diligence reference.

Available Through Controlled Request

Detailed penetration-test material, internal control documentation, risk information, security questionnaires, business-continuity evidence and other commercially or technically sensitive records.

Disclosure is assessed according to the requester, purpose, customer status, document sensitivity and any required confidentiality agreement.

RESPONSIBLE AI

AI Can Assist the Work. It Does Not Own the Decision.

Where approved AI capability is used, it may help interrogate authorised information, generate summaries or support content through defined prompts. Customers can determine whether optional AI functionality is appropriate for their environment.

AI does not become the control owner, approve evidence, interpret legal duties, accept risk or make assurance decisions. Competent people remain responsible for the source information, prompt, review, decision and resulting action.

Customer information is not presented as training material for public models. The applicable service configuration, processing role, contractual position and supplier arrangements remain subject to the agreed customer scope.

Human responsibility remains explicit

Authorised input
Only information permitted for the approved purpose.

Review before reliance
Outputs are checked by a responsible person.

No invented evidence
AI must not fabricate records, controls, approvals or results.

Decision ownership
Accountability remains with competent and authorised people.

PRACTICAL QUESTIONS

Zebsoft Trust Centre FAQs

These answers describe the general Trust Centre route. Customer-specific commitments remain governed by the applicable proposal, contract, data-processing terms and agreed service configuration.

What is the Zebsoft Trust Centre?

It is the central public route for understanding Zebsoft security, privacy, resilience, responsible-AI and corporate commitments, together with the evidence-request process.

Does ISO/IEC 27001 certification cover every customer obligation?

No. Certification applies to the management system and scope stated on the certificate. Customers must still assess their own requirements, configuration, use and contractual obligations.

Where is the platform hosted?

The Zebsoft cloud platform is hosted in AWS London. Any customer-specific architecture or additional service arrangement should be confirmed through the agreed scope.

Can we receive a security questionnaire?

Yes. Provide the questionnaire, purpose, deadline and relevant opportunity or customer relationship. Zebsoft will determine the appropriate response and evidence route.

Are penetration-test reports public?

Detailed reports are not published openly. Relevant evidence may be shared through a controlled process depending on sensitivity, purpose, customer status and confidentiality arrangements.

Does Zebsoft use customer data to train public AI models?

Zebsoft does not present customer information as training material for public models. Optional AI use remains governed by the applicable service configuration and processing arrangements.

How do we report a suspected vulnerability?

Use the security contact route and provide sufficient detail for safe investigation. Do not publicly disclose or exploit a suspected vulnerability while Zebsoft assesses it.

How current is the information?

Trust Centre content is reviewed periodically and when relevant changes occur. Certificates, reports and contractual evidence should always be checked for their individual version, scope and validity.

NEED FORMAL ASSURANCE INFORMATION?

Request the Evidence Appropriate to Your Review

Tell us what your procurement, security, privacy or assurance review requires. We will identify what can be supplied publicly, what requires controlled disclosure and what depends on the proposed service scope.