Security at Zasio

Information Security

We take information security seriously. Keeping your data secure is our highest priority and we are committed to protecting customer data across all our services — with a SOC 2 Type 2 attestation (AICPA Trusted Service Criteria, third-party audited) available to customers and prospects on a confidential basis.

Request the SOC 2 reportProduct security & trust

SOC 2 TYPE 2 ATTESTATIONIndependent Service Auditor’s ReportAICPA Trusted Service CriteriaWHAT IT TELLS YOUR REVIEW TEAMControls tested in operation over time, not a single dayAudited by an independent third partyScope spans the organization — not just the productAvailable to customers & prospects under NDA
Fig. 1 — The report behind the claims, available on request.
AICPA SOC for Service Organizations
SOC 2 Type 2AICPA Trusted Service Criteria · independent auditor · organization-wide scope
Silent Sector penetration test — verified 2025
Penetration test — verified 2025Annual third-party test by Silent Sector, plus monthly SaaS application scans

Our SOC 2, Type 2 attestation

Zasio has demonstrated its commitment to information security through our SOC 2, Type 2 attestation report, which we provide to our customers and prospects on a confidential basis. Our SOC 2 attestation is based on the American Institute of Certified Public Accountants ("AICPA") Trusted Service Criteria and is provided by a third-party auditor.

While dedicated to our SaaS solutions, the majority of the described processes and controls apply throughout our organization. A SOC 2 report is one of the most industry-accepted auditing standards for a service company to demonstrate that its business processes, information technology, and risk management controls are properly designed. To request a copy of Zasio's most recent SOC 2, Type 2 report, please contact your account executive or fill out this form.

How we run security

Comprehensive ISMS

To help ensure our information security practices remain at the leading edge of our industry, Zasio has implemented and maintains a comprehensive written Information Security Management System (ISMS) to manage and protect Zasio’s business information, as well as the data and information entrusted to us by our customers. All security and privacy-related policies and procedures within our ISMS are documented, approved by executive management, communicated to all Zasio personnel, and reviewed and updated at least annually.

Network security

Zasio maintains industry-standard technologies and controls to protect network security, including firewalls, intrusion prevention, monitoring, network segmentation, and VPN and wireless security. We review our network designs and controls at least annually, and utilize a dedicated firewall/proxy appliance with an enhanced security subscription to help ensure that all communications attempting to cross our network boundary comply with our documented security policy — several layers of protection are enabled within this firewall for maximum security. Zasio further utilizes an industry-standard malware protection strategy designed to effectively and efficiently prevent network viruses and other malware outbreaks, as well as prevent network security attacks.

Vulnerability testing

We undergo annual penetration testing of our information systems infrastructure by a qualified third party (Silent Sector, verified 2025). Additionally, Zasio has web application scans in connection with our SaaS offerings performed monthly by a qualified third party.

Software secure development and lifecycle

We maintain a software secure development lifecycle policy to ensure security by design within the development lifecycle for applications and information systems.

Data backup and recovery

Zasio maintains a formal backup and recovery plan to guard against loss and to establish recovery time (RTO) and recovery point (RPO) objectives in the event of any unplanned system outage. Hosting facility backups: each database and dedicated server in Zasio’s hosting facilities is backed up daily, with each backup stored at least two weeks and up to four depending on customer configuration — the first two weeks in the same physical site as the hosted system, followed by an additional two weeks of offsite storage in a separate, secure facility. Internal backups: Zasio’s on-premises major systems, including Active Directory catalogs, email servers, document stores, production databases and application servers running critical business functions, are fully backed up weekly with backup media rotated offsite to a secure location, and incremental backups of active document repositories captured every two hours. Zasio tests both internal and hosted backup and recovery systems at least annually.

Infrastructure security

We use Microsoft Azure as our third-party hosting facility provider in connection with our SaaS offerings; these providers are responsible for protecting the infrastructure used to provide our cloud-based services. Zasio further protects our cloud infrastructure: for our SaaS offerings Zasio maintains separate hosted databases for each customer, with permissions that only allow user access to the one database that customer is associated with. Zasio also maintains separate internal production and test database servers to protect against unauthorized access to customer data.

Information security incident response planning

We maintain a formal information security incident response plan which shall be activated in the event of any information security incident or related event. Zasio maintains a record of any information security breach with a breach description, the time period, the consequences of the breach, the identity of the reporter, and the procedure for recovering data.

Encryption

Zasio utilizes strong encryption of customer data both in transit and at rest. All internet traffic is secured using TLS 1.2 (minimum), AES 256, with a 2048 bit signed certificate. The databases for our hosted applications are encrypted at rest using AES 256.

Security training

We conduct annual security awareness training for all personnel and provide security awareness updates at least quarterly.

Third-party management

Zasio maintains a third-party management policy to help ensure information shared with, accessible to, or managed by third parties is properly protected. This policy establishes standards for how we select third-party IT vendors, evaluate vendor information security practices and risks, and monitor these risks.

For your review team

Answers before the questionnaire.

The SOC 2 Type 2 report plus our technical and organizational measures cover most security reviews on day one — customers tell us it shortens the whole process. For additional information about Zasio's information security practices, please review our Technical and Organizational Measures.

Request documentation →

In the product

SSO, two-factor authentication, per-customer database isolation, and view-level audit trails live on the product side.

Versatile security & trust →