Skip to content
Zorix Systems — software that powers your business

How we work

Security and compliance

Every entry below is either confirmed in writing or marked as unconfirmed. We do not display certification badges, and we will not state that we hold a certification until the certificate and its scope statement can be sent to you.

A supplier who overstates a certification in a procurement response creates a contractual and regulatory problem for the buyer as well as themselves. Ask us for the certificate; if there is not one, this page will say so.

Certification

Certification

ISO 27001
Information security management system
Available on request during due diligence
ISO 9001
Quality management system
Available on request during due diligence
Cyber Essentials Plus
UK government-backed technical controls scheme
Available on request during due diligence
SOC 2
Type I or Type II service organisation report
Available on request during due diligence

Insurance and continuity

Insurance and continuity

Professional indemnity
Cover level per claim and in aggregate
Available on request during due diligence
Public liability
Cover level
Available on request during due diligence
Employer's liability
Cover level
Available on request during due diligence
Source code escrow
Provider and agreement type
Available on request during due diligence

Data protection

Data protection

UK GDPR position
Controller/processor role, ICO registration, DPO or lead contact
Available on request during due diligence
EU GDPR position
EU representative and lawful transfer mechanism
Available on request during due diligence
International transfers
IDTA or UK Addendum plus Transfer Risk Assessment
Available on request during due diligence

Sector-specific

Sector-specific

HIPAA readiness
Business associate agreement position
Available on request during due diligence
NHS DTAC
Digital Technology Assessment Criteria completion
Available on request during due diligence
DCB0129 / DCB0160
Clinical risk management standards for health IT
Available on request during due diligence
DSPT
NHS Data Security and Protection Toolkit submission
Available on request during due diligence

Engineering practice

Controls we apply on every engagement

Independently of certification status, the following apply to all delivery work: least-privilege access issued through your identity provider with multi-factor authentication; monthly access review and revocation within one business day of a person leaving a pod; mandatory peer review before merge; automated dependency and secret scanning in the pipeline; no production personal data in development or test environments; encryption in transit and at rest; and audit logging of privileged actions.

Penetration testing by an independent CREST-registered provider can be arranged before release and is priced as a line item rather than assumed. Findings are remediated and retested before go-live, and the report goes to you unedited.

Send us your security questionnaire.

We will complete it with evidence attached, and mark anything we cannot evidence as not held.

Talk to us