Security Dashboard · Last updated October 4, 2026

Independent assurance, ready for review

Zentrik completed an independent SOC 2 Type II examination of the Zentrik Platform against the Security criteria, covering how its controls operated from June to September 2026. Request the report through our Trust Center or review the current control posture below.

Report requests are reviewed manually. Access is limited to customer and qualified prospect diligence and may be subject to an NDA.

Quick answers

TopicStatusDetails
Public model trainingNoCustomer data is not used to train public AI models. Private-model options may be available by request and configuration.
SOC 2 statusSOC 2 Type II report issuedTests how controls operated against the Security criteria from June 4 to September 4, 2026. Issued October 2, 2026 by Advantage Partners: unqualified, no exceptions noted.
EncryptionTLS 1.2+ / at restTLS 1.2+ in transit and provider-managed encryption at rest for Postgres and object storage.
Backups and export30-day SLAEncrypted nightly backups with 5-day retention (rolling). One-time export or deletion requests are completed within 30 days of a verified request.

Program evidence: Request the SOC 2 Type II report

Access controls

  • Workspace access is enforced at the application layer by membership checks on workspace-scoped routes.
  • Role-based access control governs privileged actions (Owner, Admin, Viewer).
  • Least-privilege access for production credentials and admin tooling.
  • Access logs are retained for at least 90 days.

Processing scope

  • Hosting, storage, and collaborative editing of Workspace Data.
  • AI-assisted content generation and workflow assistance.
  • Optional product analytics is limited to region-appropriate usage events and opaque application identifiers.
  • Support, maintenance, security monitoring, and service improvement as permitted by the Terms and any executed DPA.

Data protection and recovery

  • Nightly encrypted snapshots retained for 5 days and purged by rotation.
  • Target restore time objective (RTO): 2 business days for incidents caused by Zentrik.
  • Target recovery point objective (RPO): time of last successful snapshot.

Security monitoring

  • Integrated monitoring of application dependencies for known vulnerabilities, with defined triage and ownership.
  • Automated checks in our build pipeline—including scheduled verification—that block critical-severity dependency or container-definition issues when those surfaces change.
  • Remediation targets: critical within 7 days; high within 30 days where feasible.

For security questionnaires or implementation detail (tooling, cadence, evidence), contact security@zentrik.ai.

AI usage and training policy

  • Customer data is not used to train public AI models.
  • AI processing runs on OpenAI through its API.
  • Private-model options may be available by request and configuration.

Analytics and telemetry

Public website page views are measured without cookies or any device-stored identifier, under a rotating server-side hash. Identified product analytics starts only after explicit consent where that consent is required. Elsewhere, it may be enabled by default and can be disabled through Privacy choices. It is limited to bounded usage events and workspace identifiers. A named product User's opaque account ID and display name may label the PostHog person profile; unnamed Users, Ideas Portal visitors, and optional service telemetry remain profileless. Browser analytics is configured not to include email addresses, Workspace content, or transcripts. The region used to decide whether consent is required is resolved on Zentrik’s own servers from a locally stored country database; no visitor IP address is sent to a third party for that decision.

Incident response

We maintain a written incident response playbook and an escalation process. Customers are notified of confirmed personal data breaches without undue delay and, where required by law, within 72 hours of awareness.

Security: security@zentrik.ai | Privacy: privacy@zentrik.ai

Processing locations and infrastructure (current)

This operational summary does not define or extend the scope of the SOC 2 report; the report defines its assessed systems and controls.

ComponentProviderRegionNotes
DatabaseFly.io managed Postgressjc (US)Primary relational data store for workspace data.
HostingFly.io machinesmad (EU) and sjc (US)Application runtime and service infrastructure.
Object storageAWS S3us-east-2 (US)Uploaded files, text extracted from them, imported source text, and generated documents.
Email deliveryPostmark (AC PM LLC)United StatesDelivery of account, product, and update email, with delivery and suppression event processing.
AI provider processingOpenAIUnited States (provider-dependent)Prompt text and the workspace context it needs, sent through the API.

International transfers

Where applicable, Zentrik can execute a DPA on request that includes standard transfer terms such as the EU Standard Contractual Clauses and the UK IDTA. Supplementary measures may include encryption in transit and at rest, access controls, and a government request handling process.

Audit and questionnaires

Zentrik’s SOC 2 Type II report is available to customers and qualified prospects through the Vanta Trust Center under access approval. We also support reasonable security questionnaires. Remote evidence review and additional materials may be available on request and, where applicable, under NDA. Any audit rights are governed by the Terms and any executed DPA.

Sub-processors

The current list of approved Sub-processors and our change-notification policy are available at https://zentrik.ai/sub-processors.

Questions

For security or privacy questions, contact security@zentrik.ai or privacy@zentrik.ai.

Company legal contact

Zentrik Company

490 Post St, Ste 500, PMB 2017

San Francisco, CA 94102, USA

Legal: legal@zentrik.ai | Privacy: privacy@zentrik.ai | Security: security@zentrik.ai