Cloudflare WAF
Managed ruleset active at enterprise sensitivity, plus custom rules locking down sensitive paths like /auditor-portal.
Zairen's product is built around a control library, continuous evidence, and least-privilege access. The platform itself is held to the same standard. Here's exactly where we stand, and what protects this site today.
Zairen is working toward SOC 2 Type II for its own platform, with the same control library and evidence model that powers the product. We won't claim a badge we haven't earned - this page will be updated the day that changes, exactly as our About page promises.
The zairen.co edge is protected by Cloudflare Enterprise, and every page ships with defense-in-depth headers set at the origin. In place today:
Managed ruleset active at enterprise sensitivity, plus custom rules locking down sensitive paths like /auditor-portal.
Zero Trust access policies in front of internal tooling and the auditor portal - email-allow-listed and audited.
HTTPS only, TLS with HSTS (2-year, preload), and full SSL between the edge and origin.
Strict CSP with no frame-ancestors and a narrow script allow-list; forms are restricted to approved endpoints.
Forms are handled by a Cloudflare Worker with a honeypot field and per-IP rate limiting - no third-party form processor.
A published security contact at /security.txt so researchers can reach us directly.
Scans run against artifacts you connect, evidence is scoped to controls rather than raw code dumps, and access is least-privilege, logged, and time-bound. The full picture lives in our Privacy Policy and DPA.
No. Static analysis runs against the artifacts you connect, and findings are mapped to control evidence rather than retained as a full copy of your source.
Scans run against the repositories and cloud environments you connect. Only the evidence needed to satisfy a control is surfaced, not a raw dump of your environment.
We retain the minimum evidence required to keep a control verifiable — scoped findings and their mappings — not your full codebase or configuration.
Read-only access to the sources you choose to connect, scoped to what's needed for analysis. You can revoke access at any time.
Disconnect the integration or revoke the token at the source. On revocation, Zairen's access stops and any retained evidence is governed by our retention and deletion policy in the DPA.
Found something on zairen.co or in Zairen's product? Write to security@zairen.co. We treat security reports as a priority and will acknowledge them promptly.
A compliance vendor should be able to show you its own health, not just ask you to trust a marketing page. Our public status page reports live site and DNS availability. View the status page.