Software/ Security & Trust
Security & Trust
Your security review just got shorter
Zasio holds a SOC 2 Type 2 attestation, available to customers and prospects on a confidential basis. For the teams that still have questions, here is how Versatile is built and run — stated plainly.
How access is controlled
Enterprise sign-in
SAML 2.0 and Microsoft Entra ID single sign-on on cloud-connected deployments; Active Directory and Windows authentication everywhere; two-factor authentication.
Granular authorization
Role-based security groups combine function-level permissions with record-scoped access by company, department, business function, country, and location — full access, read-only, or none.
Approvals with teeth
Destruction runs can require named authorizers and e-signature verification before anything is destroyed.
How the platform is built and run
Tenant isolation
Every SaaS customer runs against their own database — your records never share a database with anyone else's.
Audit trail, down to views
Adds, updates, deletions, approvals, destructions — and viewings — are captured across the platform with user and timestamp.
Deterministic by design
Retention calculation and destruction are rules-based and fully deterministic. AI never decides what is destroyed.
Encrypted transport
All client-server communication is TLS-secured.
Managed updates
Software and database schema updates are centrally managed across servers and clients — no unpatched stragglers.
AI with governance
The Versatile Information Assistant runs on Zasio infrastructure and is never sent to third-party or public AI providers. Your questions go to VIA; your records never do.
