Controlled access
The security baseline calls for named accounts, least-privilege permissions and multi-factor authentication for privileged administration.
Our security approach covers customer access, infrastructure administration and the lifecycle of customer data. Controls and responsibilities are defined for each engagement.
The security baseline calls for named accounts, least-privilege permissions and multi-factor authentication for privileged administration.
Customer workloads, management interfaces and storage require an isolation model appropriate to the contracted service.
Security events, privileged activity and changes need a documented logging, retention and incident-handling process.
The security requirements for each engagement cover:
Discuss implementation details and validation requirements directly with our team.
Zenview’s responsibilities for the provisioned infrastructure, model-serving layer and support will be defined in the service agreement. Customers remain responsible for their authorised users, application security, model and data rights, and lawful workloads.
Backup arrangements, data retention, recovery objectives and support commitments must be agreed for the selected service; they are not inferred from the location of the data centre.
Send security reports to admin@zenviewlabs.com. Include the affected service or page, a description of the issue and safe reproduction details. Please do not include customer data, passwords or private keys.
Testing must remain within systems you are authorised to assess. See the Acceptable Use Policy.
Discuss your identity, isolation, data-handling and assurance requirements before an engagement begins.