SOC2C

Is this your company? Buyers are checking Zeronorth Technologies here. Claim zeronorth.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Zeronorth Technologies logo

Zeronorth Technologies

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Zeronorth Technologies is SOC 2 Type II compliant. Zeronorth Technologies also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

At ZeroNorth, security is of the utmost importance to us. We believe that it is our responsibility to protect our customers' data and maintain the privacy and confidentiality of their information. To achieve this, we have implemented robust security measures, including regular security audits and testing, access controls, encryption, and monitoring to ensure the integrity of our systems. We also prioritize educating our employees and customers on best security practices to maintain a culture of security awareness throughout the organization. Ultimately, we are committed to continuously improvi

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

3

Subprocessors

9
  • A
    Amazon Web Services · aws
  • A
    Auth0
  • S
    Salesforce.com
  • I
    Intercom
  • D
    Datadog · datadog
  • S
    Snowflake · snowflake
  • M
    MapTiler Cloud
  • G
    GitHub · github
  • G
    Google Workspace · gsuiteadmin

Compliance leadership

The person who leads Zeronorth Technologies's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Zeronorth Technologies's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Zeronorth Technologies SOC 2 compliant?
Zeronorth Technologies is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Zeronorth Technologies ISO 27001 certified?
According to Zeronorth Technologies's public trust center, Zeronorth Technologies is ISO 27001 certified. On SOC2C this listing is Listed.
Is Zeronorth Technologies SOC 2 Type I or Type II?
Zeronorth Technologies is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Zeronorth Technologies's SOC 2 for a vendor risk assessment?
Yes. Zeronorth Technologies's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Zeronorth Technologies penetration tested?
Zeronorth Technologies hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Zeronorth Technologies

Reproduced from Zeronorth Technologies's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Who can see my information?
Access to the data is available only through the restricted access control layer implemented through the application. We also use various encryption techniques to ensure data residing on the cloud and data transferring over the cloud is protected and accessible only by the authorized users. The following entities or users are covered by this policy: • Full or part-time employees of ZeroNorth who have access to ZeroNorth or customer data. • ZeroNorth vendors or processors who have access to ZeroNorth or customer data. • Other persons, entities, or organizations that have access to ZeroNorth or customer data. All network, system, and application events must only result from allowable actions through access control mechanisms. Permission may be derived directly from an individual’s identity, or from a job classification or administrative privilege based on that individual’s identity. The principle of “least privilege” specifies that individuals only be granted permission for actions needed to perform their jobs. Limiting actions to those properly authorized protects the confidentiality and integrity of data within the ZeroNorth processing environment. In this context, access control refers to a security service that allows or denies a user request based on privilege, group information, or context. Confidentiality refers to a security service that prevents disclosure of information to unauthorized parties while the information is in use or transit or being stored.
How much control do I retain over my data?
Clients have complete control as well as ownership of their data. With necessary access credentials, Client users can access data anytime, anywhere in the world.
Will ZeroNorth use my data?
ZeroNorth will, unless otherwise specified by the client, aggregate any and all data entered the application to formulate anonymized voyage data, trends and insights that would be beneficial to voyage management. ZeroNorth takes the utmost care in anonymizing this aggregated data so anything published or sent externally could not be identified or tied to any one client of the application.
How is activity in my account monitored and tracked?
Appropriate logging techniques are in place at the AWS, local operating system and database levels to capture valuable metrics and events. At the individual application level, audit control is maintained with clear indication of user, date/time capture on creation and modification of data.
Do you encrypt data at rest?
Data is encrypted with industry standard AES-256 encryption algorithm in both transit and at rest.

Business & Industrial peers that completed SOC 2