{"schemaVersion":"1.0","name":"Zephior Trust Center","url":"https://trust.zephior.com","reviewedAt":"2026-08-30","description":"Security assurance, privacy resources and controlled access to Zephior compliance documents.","audit":{"name":"SOC 2 Type II","status":"Report available on request","scope":"The AI enterprise RFP management platform described in the report","periodStart":"2024-10-31","periodEnd":"2025-01-31","issuedAt":"2025-10-17","auditor":"Prescient Assurance LLC","criteria":["Security","Confidentiality","Availability"],"opinion":"Unmodified opinion for the examination period","limitation":"The examination covers the described system and historical period. It does not attest to every current product, deployment or control."},"frameworks":[{"name":"ISO/IEC 27001","subject":"Information security management","status":"Certification preparation"},{"name":"ISO/IEC 42001","subject":"AI management systems","status":"Programme preparation"}],"controls":[{"name":"Security governance","description":"Security responsibilities, documented policies and oversight."},{"name":"Risk management","description":"Identification, assessment and treatment of security risks."},{"name":"Identity and access","description":"Authorized access, least privilege and access lifecycle reviews."},{"name":"Data protection","description":"Protection of sensitive information in storage and transmission."},{"name":"Secure development","description":"Development practices and review of production changes."},{"name":"Vulnerability management","description":"Vulnerability assessment, prioritization and remediation processes."},{"name":"Security monitoring","description":"Logging and monitoring of security-relevant events."},{"name":"Incident preparedness","description":"Response responsibilities, procedures and exercises."},{"name":"Continuity and recovery","description":"Continuity planning, backups and recovery controls."},{"name":"Information lifecycle","description":"Data classification, confidentiality, retention and disposal policies."},{"name":"Personnel security","description":"Security awareness, confidentiality obligations and personnel lifecycle controls."},{"name":"Third-party risk","description":"Vendor review and contractual security obligations."},{"name":"Asset management","description":"Asset inventory, configuration and system-hardening processes."}],"controlsScope":"These are control areas addressed in the SOC 2 examination, not a live control-status feed. The report contains the scope, testing and qualifications.","documents":[{"id":"soc2","name":"SOC 2 Type II report","access":"Restricted","description":"Independent examination report. Available to eligible parties following review."},{"id":"privacy","name":"Privacy notice","access":"Public","url":"https://zephior.com/privacy"},{"id":"dpa","name":"Data processing agreement","access":"Public","url":"https://zephior.com/dpa"},{"id":"terms","name":"Terms of service","access":"Public","url":"https://zephior.com/terms"}],"access":{"requestUrl":"https://trust.zephior.com/#documents","policy":"Restricted reports require a verified email address, an eligible business purpose and individual approval. Access is time-limited and may be revoked. Documents must not be redistributed."}}