Trust Center
Security and compliance buyers can verify before they buy.
ZonForge publishes its current security posture, compliance roadmap, uptime expectations, data protection commitments, and customer-facing trust documents in one place.
All Systems OperationalPublic site and app shell are available. Historical uptime dashboard is planned.
SOC 2 Type IIIn progress. Do not treat ZonForge as SOC 2 certified until the audit is complete.
ISO 27001 AlignedControls are aligned; formal audit status must be confirmed during procurement.
Buyer Trust Packet
| Area | Current website proof | Status |
|---|---|---|
| Security measures | Security Addendum covers encryption, MFA, RBAC, audit logging, tenant isolation, incident response, and DR posture. | Published |
| Data processing | DPA covers GDPR/CCPA processing scope, subprocessors, breach notice, deletion, and audit rights. | Published |
| Capability truth | Capability Status is the source of truth for production-ready, sandbox, in-development, and planned capability claims. | Published |
| Uptime history | Public historical uptime and incident timeline should be connected to the operational status system. | Planned |
| Incident history | Security and availability incident records should be published when material incidents occur. | Planned |
Enterprise Commitments
Approval-gated responseDestructive or high-risk actions require explicit authorization and auditability.
Tenant isolationCustomer data is scoped by tenant boundaries and least-privilege access controls.
Verified claimsMarketing claims must remain consistent with the capability status page.
ZonForge Sentinel