Skip to content
Security & Compliance Dossier

Standing evidence of how we handle your data.

This dossier is the single canonical reference for Zetamu's enterprise trust posture — the certifications we hold, the controls we operate, and the way learner data is stored, processed, and audited across our San Francisco, Lisbon, and Singapore offices. It is built for CISOs, procurement teams, and security reviewers, and is updated quarterly alongside our external attestations.

Last refreshed14 January 2026
Reporting periodFY2025 Q4
Next attest refreshQ2 2026
Section 01 — Certifications

Four certifications a reviewer needs to see first.

We hold each of the certifications an enterprise procurement team will ask about, and we publish the underlying audit cadence here so the request form below is the last step rather than the first.

01

SOC 2 Type II

Annual independent audit of the Security, Availability, and Confidentiality Trust Services Criteria. Latest report covers 12 consecutive months of operating effectiveness.

AuditorVerdant Analytics LLP
Last issuedJanuary 2026
Coverage12-month window
Request the report
02

ISO/IEC 27001:2022

Information Security Management System certified to the 2022 revision. Statement of Applicability covers 93 Annex A controls across all three Zetamu regions.

Cert bodyBSI Group
Cert no.IS 781204
SurveillanceAnnual + surprise
Download SoA summary
03

GDPR-Certified

Certified under the EuroPriSe and CNIL reference frameworks for EU/EEA learner data. Data Processing Agreement is countersigned within two business days of request.

FrameworkEuroPriSe + CNIL
DPA turnaround≤ 2 business days
Read the DPA terms
04

Additional frameworks

ISO 27017 (cloud-specific controls), ISO 27018 (PII protection in public cloud), and HIPAA-aligned operational practices for US healthcare-sector customers handling workforce training data.

ISO 27017Certified 2024
ISO 27018Certified 2024
Pen testsBi-annual, public summary
See control domains

Request the SOC 2 Type II report.

The report is released under a current mutual NDA to verified domains. We typically respond within one business day. For enterprise procurement, please use your company email rather than a personal address.

Section 02 — Data residency

Where learners live, where data lives, and which regime applies.

Zetamu operates three production regions on isolated infrastructure. Enterprise customers select their residency tier at contract signing; the platform enforces data locality at the storage, processing, and backup layers — not just at the network edge.

Operating regions PrimarySecondary
Editorial duotone world map with pins marking Zetamu's San Francisco, Lisbon, and Singapore operating regions.
Projected coordinate: equal-area projection, markers placed by capital city.
RegionRegulatory regimeStorage tierAvailable for
San Francisco
us-west-2
SOC 2 · CCPA · HIPAA-aligned Primary North & South America customers
Lisbon
eu-west-1
GDPR · ISO 27001 · EuroPriSe Primary EU/EEA & UK customers
Singapore
ap-southeast-1
PDPA · ISO 27001 · MAS-TRMG Secondary (failover) APAC customers & cross-region DR
Section 03 — Control architecture

The four control families a CISO will forward to their questionnaire.

Each domain below is described to questionnaire depth — enough for a procurement reviewer to mark the box, without dumping the full SOC 2 report into a marketing page. Detailed control mappings are returned with the SOC 2 Type II report.

A

Identity, access & authentication

Every administrative and learner action passes through a single identity plane. Customer administrators enforce their own RBAC; Zetamu never holds super-admin credentials on the customer's behalf.

  • SSO. SAML 2.0 and OIDC with enforced IdP-initiated flows; SCIM 2.0 for user provisioning and deprovisioning across Okta, Entra ID, Google Workspace, and Ping.
  • RBAC. Four base roles (Learner, Manager, Admin, Auditor) with custom role builder; permissions audited quarterly against least-privilege baseline.
  • MFA. Hardware-key and TOTP required for all Zetamu staff with production access; FIDO2 preferred for customer administrators.
  • Session. 30-minute idle timeout on administrative consoles; learner sessions refresh on inactivity but persist across devices.
B

Encryption & key management

Learner data is encrypted in transit and at rest using AES-256, with key material held under customer-controlled options for enterprise tiers.

  • In transit. TLS 1.3 only across all public and internal endpoints; legacy ciphers disabled at the load balancer.
  • At rest. AES-256 on all primary storage, backups, and object stores; envelope encryption with rotating KMS keys.
  • Key custody. AWS KMS by default; customer-managed CMK (HSM-backed) available on Enterprise tier with annual key rotation.
  • Secrets. No production secrets in code or environment files; runtime resolution through a sealed-secret operator with audit logging.
C

Vendor & supply-chain risk

Every named subprocessor is reviewed annually against ISO 27001 supplier controls and listed in a public subprocessor registry. Material changes trigger a 30-day customer notice.

  • Cloud. AWS (primary), Cloudflare (edge), Snowflake (analytics warehouse) — all SOC 2 Type II and ISO 27001 certified.
  • Identity. Okta and Auth0 for internal staff SSO; no learner PII shared with identity providers beyond hashed identifiers.
  • AI. Zia inference runs on isolated tenant infrastructure; no learner content is used to train shared models.
  • Notice. Subprocessor changes are announced via the trust portal and via email to enterprise account contacts at least 30 days ahead.
D

Incident response & business continuity

A documented 24/7 incident response process is rehearsed quarterly. Customers receive timely, accurate notice — never a marketing rephrasing of the facts.

  • Detection. 24/7 SOC with 5-minute median time-to-page on Sev-1 alerts; runbooks reviewed after every incident.
  • Notice SLA. Confirmed security incidents affecting customer data are reported within 72 hours, per GDPR Art. 33 and contractual terms.
  • BC/DR. RPO 15 minutes, RTO 1 hour, validated by quarterly cross-region failover drills (Lisbon ↔ Singapore).
  • Post-incident. Customer-facing PIRs published within 14 days for Sev-1 and Sev-2 incidents; root-cause actions tracked to closure.
Operational track record

What the certifications are resting on.

1,840,000+
Active learners operating under the controls described above, across 312 enterprise customers and three production regions.
0open
Open audit observations from the current SOC 2 Type II reporting period — the fourth consecutive clean attestation since FY2023.
5years
Consecutive years of SOC 2 Type II coverage with no material exceptions, since Zetamu's founding certification in March 2021.
Section 05 — Reviewer FAQ

Answers to the questions your procurement team would otherwise email us.

01Who are Zetamu's subprocessors, and how are changes announced?

The full subprocessor registry is published on our trust portal and refreshed within 5 business days of any change. Material additions or replacements trigger a 30-day customer notice by email to enterprise account contacts; routine replacements (e.g., a regional CDN failover) are listed on the portal with a brief rationale. No subprocessor ever receives raw learner PII beyond what is strictly necessary for the service it provides.

02What is your breach-notification SLA?

Confirmed security incidents affecting customer data are reported without undue delay and in any case within 72 hours of confirmation, per GDPR Article 33 and contractual terms. Customer-facing post-incident reports are published within 14 days for Sev-1 and Sev-2 incidents, and shared privately with named security contacts on lower-severity issues.

03What encryption standards do you operate?

TLS 1.3 in transit across all public and internal endpoints, AES-256 at rest on all storage tiers, and envelope encryption with rotating KMS keys. Enterprise customers can opt for customer-managed CMK (HSM-backed) with annual key rotation. Legacy ciphers and protocols (TLS 1.0, 1.1, SSLv3) are disabled at the load balancer.

04How is learner data deleted at end of contract?

On contract termination, all customer learner data is deleted from primary storage within 30 days and from backups within 90 days. A signed certificate of deletion, naming the data scope and the deletion timestamp, is issued by the Zetamu Security Officer within 14 days of completion. EU/EEA customers may also request earlier deletion under GDPR Article 17.

Still missing an answer?

Send a one-line question to [email protected] — most replies arrive within one business day. For a live walkthrough with our security lead, request a Capability Assessment and we will route the meeting to the right reviewer on our side.