SOC 2 Type II
Annual independent audit of the Security, Availability, and Confidentiality Trust Services Criteria. Latest report covers 12 consecutive months of operating effectiveness.
Request the reportThis dossier is the single canonical reference for Zetamu's enterprise trust posture — the certifications we hold, the controls we operate, and the way learner data is stored, processed, and audited across our San Francisco, Lisbon, and Singapore offices. It is built for CISOs, procurement teams, and security reviewers, and is updated quarterly alongside our external attestations.
We hold each of the certifications an enterprise procurement team will ask about, and we publish the underlying audit cadence here so the request form below is the last step rather than the first.
Annual independent audit of the Security, Availability, and Confidentiality Trust Services Criteria. Latest report covers 12 consecutive months of operating effectiveness.
Request the reportInformation Security Management System certified to the 2022 revision. Statement of Applicability covers 93 Annex A controls across all three Zetamu regions.
Download SoA summaryCertified under the EuroPriSe and CNIL reference frameworks for EU/EEA learner data. Data Processing Agreement is countersigned within two business days of request.
Read the DPA termsISO 27017 (cloud-specific controls), ISO 27018 (PII protection in public cloud), and HIPAA-aligned operational practices for US healthcare-sector customers handling workforce training data.
See control domainsThe report is released under a current mutual NDA to verified domains. We typically respond within one business day. For enterprise procurement, please use your company email rather than a personal address.
Zetamu operates three production regions on isolated infrastructure. Enterprise customers select their residency tier at contract signing; the platform enforces data locality at the storage, processing, and backup layers — not just at the network edge.
| Region | Regulatory regime | Storage tier | Available for |
|---|---|---|---|
| San Francisco us-west-2 |
SOC 2 · CCPA · HIPAA-aligned | Primary | North & South America customers |
| Lisbon eu-west-1 |
GDPR · ISO 27001 · EuroPriSe | Primary | EU/EEA & UK customers |
| Singapore ap-southeast-1 |
PDPA · ISO 27001 · MAS-TRMG | Secondary (failover) | APAC customers & cross-region DR |
Each domain below is described to questionnaire depth — enough for a procurement reviewer to mark the box, without dumping the full SOC 2 report into a marketing page. Detailed control mappings are returned with the SOC 2 Type II report.
Every administrative and learner action passes through a single identity plane. Customer administrators enforce their own RBAC; Zetamu never holds super-admin credentials on the customer's behalf.
Learner data is encrypted in transit and at rest using AES-256, with key material held under customer-controlled options for enterprise tiers.
Every named subprocessor is reviewed annually against ISO 27001 supplier controls and listed in a public subprocessor registry. Material changes trigger a 30-day customer notice.
A documented 24/7 incident response process is rehearsed quarterly. Customers receive timely, accurate notice — never a marketing rephrasing of the facts.
The full subprocessor registry is published on our trust portal and refreshed within 5 business days of any change. Material additions or replacements trigger a 30-day customer notice by email to enterprise account contacts; routine replacements (e.g., a regional CDN failover) are listed on the portal with a brief rationale. No subprocessor ever receives raw learner PII beyond what is strictly necessary for the service it provides.
Confirmed security incidents affecting customer data are reported without undue delay and in any case within 72 hours of confirmation, per GDPR Article 33 and contractual terms. Customer-facing post-incident reports are published within 14 days for Sev-1 and Sev-2 incidents, and shared privately with named security contacts on lower-severity issues.
TLS 1.3 in transit across all public and internal endpoints, AES-256 at rest on all storage tiers, and envelope encryption with rotating KMS keys. Enterprise customers can opt for customer-managed CMK (HSM-backed) with annual key rotation. Legacy ciphers and protocols (TLS 1.0, 1.1, SSLv3) are disabled at the load balancer.
On contract termination, all customer learner data is deleted from primary storage within 30 days and from backups within 90 days. A signed certificate of deletion, naming the data scope and the deletion timestamp, is issued by the Zetamu Security Officer within 14 days of completion. EU/EEA customers may also request earlier deletion under GDPR Article 17.
Send a one-line question to [email protected] — most replies arrive within one business day. For a live walkthrough with our security lead, request a Capability Assessment and we will route the meeting to the right reviewer on our side.