Software/ Security & Trust
Security & Trust
Your security review just got shorter
Zasio holds a SOC 2 Type 2 attestation, available to customers and prospects on a confidential basis. For the teams that still have questions, here is how Versatile is built and run — stated plainly.
How access is controlled
Enterprise sign-in
SAML 2.0 and Microsoft Entra ID single sign-on on cloud-connected deployments; Active Directory and Windows authentication everywhere; two-factor authentication.
Granular authorization
Role-based security groups combine function-level permissions with record-scoped access by company, department, business function, country, and location: full access, read-only, or none.
Approvals with teeth
Destruction runs can require named authorizers and e-signature verification before anything is destroyed.
How the platform is built and run
Tenant isolation
Every SaaS customer runs against their own database: your records never share a database with anyone else's.
Audit trail, down to views
Adds, updates, deletions, approvals, destructions — and viewings — are captured across the platform with user and timestamp.
Deterministic by design
Retention calculation and destruction are rules-based and fully deterministic. AI never decides what is destroyed.
Encrypted transport
All client-server communication is TLS-secured.
Managed updates
Software and database schema updates are centrally managed across servers and clients, so there are no unpatched stragglers.
AI with governance
The Versatile Information Assistant runs on Zasio infrastructure and is never sent to third-party or public AI providers. Your questions go to VIA; your records never do.
