SECURITY AND COMPLIANCE

Built for institutions that require proof.

Security posture, compliance documentation, encryption standards, and incident response. All published. All verifiable.

NDPR
Compliant
ISO 27001
Aligned controls
SOC 2
Type II in progress
CERTIFICATIONS AND FRAMEWORKS

Standards we are measured against.

01

NDPR Compliance

Full compliance with the Nigeria Data Protection Regulation. Data classification, consent management, retention policies, and processing records documented and audited.

02

ISO 27001 Aligned

Information security management system aligned to ISO 27001:2022 controls. Access control, cryptography, operations security, and supplier relationships all documented.

03

SOC 2 Type II (In Progress)

Audit underway with an independent CPA firm. Trust Services Criteria covering security, availability, and confidentiality. Report available upon completion.

04

NITDA Registered

Registered technology provider with the National Information Technology Development Agency. Registration documentation available for procurement.

05

NIST CSF Aligned

Security practices mapped to the NIST Cybersecurity Framework. Identify, protect, detect, respond, and recover functions are all covered.

06

WCAG 2.2 AA

All customer-facing interfaces and internal tools designed to WCAG 2.2 Level AA accessibility standards. Verified through automated and manual testing.

ENCRYPTION AND DATA HANDLING

How we protect data.

Every system we operate applies encryption, access control, and audit logging to data at every stage of its lifecycle.

01

Encryption in transit

TLS 1.2 minimum, TLS 1.3 preferred. HSTS enforced. All internal service-to-service communication encrypted with mutual TLS.

02

Encryption at rest

AES-256 encryption for all stored data, including databases, backups, and object storage. Keys managed via cloud KMS or HSM.

03

Access control

Least privilege by default. Multi-factor authentication required for all administrative access. Access reviews conducted quarterly.

04

Audit logging

All authentication, authorization, and data access events logged immutably. Logs retained per policy and available for audit review.

05

Data residency

Client data stored in the region specified in your agreement. African and European regions supported. Data never leaves the agreed jurisdiction.

06

Data retention and deletion

Documented retention schedules per data category. Secure deletion on contract termination with certificates of destruction available.

SECURITY OPERATIONS

How we detect and respond.

01

Continuous monitoring

24/7 monitoring of all managed systems for anomalous behavior, failed authentications, privilege escalations, and data access patterns.

02

Vulnerability management

Automated scanning of dependencies, container images, and infrastructure. Critical vulnerabilities patched within 7 days. High within 30 days.

03

Penetration testing

Independent third-party penetration testing conducted at least twice per year. All findings remediated and documented.

04

Incident response

Documented incident response plan. Triage within 15 minutes for critical events. Client notification within 24 hours of confirmed breach.

05

Backup and recovery

Automated daily backups encrypted at rest. Monthly restore drills. Recovery point and time objectives defined per system.

06

Business continuity

Documented business continuity plan, tested annually. Multi-region failover for critical systems. Recovery objectives published per service.

SUBPROCESSORS

Who we work with.

We are transparent about every third party that processes client data. The full subprocessor list is maintained and available on request.

01

Cloud infrastructure

Google Cloud Platform and Amazon Web Services. Both covered by enterprise DPAs and standard contractual clauses.

02

Communication and support

Google Workspace for internal email and collaboration. Zendesk or equivalent for client support if used.

03

Monitoring and error tracking

Sentry for application error tracking. Grafana Cloud or self-hosted Prometheus for metrics. No client PII included in telemetry.

04

Payment processing

Paystack for Nigerian transactions, PayFast for South African transactions. Card data is never stored on our infrastructure.

SECURITY DOCUMENTS AVAILABLE

What we will send you.

Verified procurement teams and security reviewers can request the following under NDA. Typical turnaround is 2 business days.

01

Security whitepaper

Full documentation of security architecture, controls, and practices. Written for technical reviewers.

02

SOC 2 report (when complete)

Independent audit report covering security, availability, and confidentiality Trust Services Criteria.

03

ISO 27001 control matrix

Mapping of our controls against ISO 27001:2022 Annex A. Includes implementation status for each control.

04

Data processing agreement

Standard DPA template ready for execution. Covers data categories, processing purposes, subprocessors, and retention.

05

Incident response plan

Documented procedures for detection, triage, containment, notification, and postmortem. Shared with enterprise clients under NDA.

06

Penetration test summary

Executive summary of most recent independent penetration test. Full report available on-site during procurement review.

VULNERABILITY DISCLOSURE

Found something? Tell us.

We welcome responsible disclosure of security vulnerabilities in our systems, products, and infrastructure. Reports are acknowledged within 24 hours and triaged within 72 hours.

security@zidosoft.dev

We do not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.

Need to complete a security review?

Send us your questionnaire or security requirements. We'll respond with the documentation your review team needs.