Universities, government bodies, and global certification programs trust zAccess with millions of exam sessions. Here's exactly how we protect them — and how you can verify it yourself.
Audited by independent third parties — not self‑attested.
Six pillars that show up in every product decision we make.
AES‑256 at rest, TLS 1.3 in transit, envelope keys rotated quarterly. Per‑tenant data keys with isolated KMS scopes.
Multi‑tenant by design: schema‑level isolation, row‑level security, and dedicated workers for high‑sensitivity workloads.
Pin tenant data to US, EU, UK, India or Australia regions. No cross‑region replication unless explicitly enabled.
SAML/OIDC SSO, SCIM provisioning, hardware‑key MFA, fine‑grained roles, and just‑in‑time elevation with full audit.
24/7 SOC, anomaly detection, runtime EDR, and weekly third‑party penetration testing on production surfaces.
Biometric templates are stored as one‑way embeddings. Candidate evidence auto‑deletes per institutional policy.
From the candidate browser to encrypted storage, every hop is authenticated, rate‑limited, and observable.
Read the whitepaperA documented, rehearsed runbook — not a hope.
Automated signals or human report opens an incident in minutes.
On‑call security engineer assigns severity and assembles response team.
Affected systems isolated; customer impact assessed and logged.
Affected admins notified with scope, timeline, and remediation.
Public RCA published; corrective actions tracked to closure.
Available under NDA via our trust portal.
Coordinated disclosure with researcher recognition and bounty awards.
One short email when the trust posture changes — never marketing.
View change history