Security

Enterprise security.
With a clear scope.

Our security approach covers customer access, infrastructure administration and the lifecycle of customer data. Controls and responsibilities are defined for each engagement.

01 / IDENTITY

Controlled access

The security baseline calls for named accounts, least-privilege permissions and multi-factor authentication for privileged administration.

02 / SEPARATION

Defined boundaries

Customer workloads, management interfaces and storage require an isolation model appropriate to the contracted service.

03 / ACCOUNTABILITY

Operational records

Security events, privileged activity and changes need a documented logging, retention and incident-handling process.

Security baseline

The security requirements for each engagement cover:

  • Named administrative identities, access approval and prompt access revocation.
  • Multi-factor authentication for privileged access, with least-privilege roles.
  • Restricted infrastructure management networks and no direct public access to server management interfaces.
  • Documented tenant separation and approved network paths.
  • Defined encryption and key-management arrangements for the selected storage and service model.
  • Security logging, vulnerability handling, incident escalation and tested data sanitisation between customers or on hardware replacement.

Discuss implementation details and validation requirements directly with our team.

Shared responsibilities

Zenview’s responsibilities for the provisioned infrastructure, model-serving layer and support will be defined in the service agreement. Customers remain responsible for their authorised users, application security, model and data rights, and lawful workloads.

Backup arrangements, data retention, recovery objectives and support commitments must be agreed for the selected service; they are not inferred from the location of the data centre.

Report a security concern

Send security reports to admin@zenviewlabs.com. Include the affected service or page, a description of the issue and safe reproduction details. Please do not include customer data, passwords or private keys.

Testing must remain within systems you are authorised to assess. See the Acceptable Use Policy.

Start a conversation

Understand the security scope.

Discuss your identity, isolation, data-handling and assurance requirements before an engagement begins.

Discuss security