Trust & Security

We sell audit-readiness. We practice it too.

Zairen's product is built around a control library, continuous evidence, and least-privilege access. The platform itself is held to the same standard. Here's exactly where we stand, and what protects this site today.

Frameworks pursuedISO 27001SOC 2PCI DSSCurrent statusIn progress - no unearned badges

Where we stand on certifications

Zairen is working toward SOC 2 Type II for its own platform, with the same control library and evidence model that powers the product. We won't claim a badge we haven't earned - this page will be updated the day that changes, exactly as our About page promises.

Security controls on this site

The zairen.co edge is protected by Cloudflare Enterprise, and every page ships with defense-in-depth headers set at the origin. In place today:

Cloudflare WAF

Managed ruleset active at enterprise sensitivity, plus custom rules locking down sensitive paths like /auditor-portal.

Cloudflare Access

Zero Trust access policies in front of internal tooling and the auditor portal - email-allow-listed and audited.

Encryption in transit

HTTPS only, TLS with HSTS (2-year, preload), and full SSL between the edge and origin.

Content Security Policy

Strict CSP with no frame-ancestors and a narrow script allow-list; forms are restricted to approved endpoints.

Spam protection on forms

Forms are handled by a Cloudflare Worker with a honeypot field and per-IP rate limiting - no third-party form processor.

security.txt

A published security contact at /security.txt so researchers can reach us directly.

How we handle your data

Scans run against artifacts you connect, evidence is scoped to controls rather than raw code dumps, and access is least-privilege, logged, and time-bound. The full picture lives in our Privacy Policy and DPA.

Code handling FAQ

Is my raw source code stored?

No. Static analysis runs against the artifacts you connect, and findings are mapped to control evidence rather than retained as a full copy of your source.

Where does scanning run?

Scans run against the repositories and cloud environments you connect. Only the evidence needed to satisfy a control is surfaced, not a raw dump of your environment.

What artifacts are retained?

We retain the minimum evidence required to keep a control verifiable — scoped findings and their mappings — not your full codebase or configuration.

What permissions does Zairen require?

Read-only access to the sources you choose to connect, scoped to what's needed for analysis. You can revoke access at any time.

How is access revoked?

Disconnect the integration or revoke the token at the source. On revocation, Zairen's access stops and any retained evidence is governed by our retention and deletion policy in the DPA.

Reporting a vulnerability

Found something on zairen.co or in Zairen's product? Write to security@zairen.co. We treat security reports as a priority and will acknowledge them promptly.

We monitor our own uptime

A compliance vendor should be able to show you its own health, not just ask you to trust a marketing page. Our public status page reports live site and DNS availability. View the status page.

Have a question about our security posture, or need a security questionnaire answered for your own review? Book a demo or write to hello@zairen.co.