Zephior Trust Center

Security you can
evaluate.

A clear view of our security assurance and the evidence behind it. Built for your due diligence.

Request documentation

Independent assurance.
Considered disclosure.

Information reviewed
01 / Independent assurance

Evidence, with context.

Scope matters
Independent examination

Security. Confidentiality.
Availability.

Zephior completed a SOC 2 Type II examination of the AI enterprise RFP management platform described in the report.

Examination period
31 Oct 2024 to 31 Jan 2025
Independent auditor
Prescient Assurance LLC
Report issued
17 October 2025
Audit opinion
Unmodified for the period

The report covers a defined system and historical period. It does not attest to every current product or deployment.

Request report

Framework direction

Programme development, separate from independent certification.

ISO/IEC 27001Information security management
Certification preparation
ISO/IEC 42001AI management systems
Programme preparation

These entries are not claims of ISO certification. Ask us about the scope and status relevant to your evaluation.

02 / Control areas

A structured security programme.

The following areas are addressed in our SOC 2 examination. Detailed controls, testing and qualifications are available in the restricted report.

01

Security governance

Security responsibilities, documented policies and oversight.

02

Risk management

Identification, assessment and treatment of security risks.

03

Identity and access

Authorized access, least privilege and access lifecycle reviews.

04

Data protection

Protection of sensitive information in storage and transmission.

05

Secure development

Development practices and review of production changes.

06

Vulnerability management

Vulnerability assessment, prioritization and remediation processes.

07

Security monitoring

Logging and monitoring of security-relevant events.

08

Incident preparedness

Response responsibilities, procedures and exercises.

09

Continuity and recovery

Continuity planning, backups and recovery controls.

10

Information lifecycle

Data classification, confidentiality, retention and disposal policies.

11

Personnel security

Security awareness, confidentiality obligations and personnel lifecycle controls.

12

Third-party risk

Vendor review and contractual security obligations.

13

Asset management

Asset inventory, configuration and system-hardening processes.

This overview describes the examination's control areas. It is not a live control-status feed or a guarantee that every control applies to every current service.

03 / Documentation

The detail, when you need it.

Public policies are open to everyone. Sensitive assurance documents are shared with eligible parties through individual review.

Already approved? Open your document access

04 / Further information

A few useful answers.

How do I access the SOC 2 report?

Submit your work email, organization and the purpose of your evaluation. After email verification, we review whether your request meets the report's intended-use conditions. Approved recipients receive time-limited access. Restricted documents must remain confidential and must not be redistributed.

Does the SOC 2 report cover every current service?

No. It covers the system described in the report for 31 October 2024 to 31 January 2025. Its scope, complementary controls and testing qualifications matter when assessing applicability. Contact us if you need assurance about a specific current service.

Where can I find privacy and contractual information?

Our privacy notice, data processing agreement and terms are publicly available. Contract-specific commitments are governed by your agreement with Zephior.

Can an agent read this trust center?

Yes. Public information is available as Markdown, JSON and through llms.txt. These resources contain the same approved public information. They do not expose restricted documents, access records or internal systems.

Have a specific due diligence question?

Talk to Zephior