Trust

Trust Centre

Version 2.0 · Effective 22 September 2026

Supplier assurance information for procurement, security, and legal teams assessing ZeroRisk Labs. Our data protection documents, our security posture, our regulatory support for DORA and NIS2, and an explicit statement of the assurance we do and do not hold.

Where detail is withheld it is withheld for a stated reason, and the route to obtaining it is given.

1. What this page is for

This is the material an enterprise procurement, security, or legal team needs in order to assess ZeroRisk Labs as a supplier. It is published rather than supplied on request so that your assessment can start before you speak to us.

Where we can state something verifiable, we state it. Where we cannot, we say so plainly rather than using language designed to imply more than we hold. For a firm that sells security assurance, overstating our own position would be disqualifying.

2. Assurance and certification position

ZeroRisk Labs does not currently hold third-party certification against ISO/IEC 27001, SOC 2, or any comparable assurance standard, and we will not represent otherwise. Where a tender requires a certified supplier, we will tell you at the outset rather than at contract stage. Independent certification of our own management system is on our roadmap, and we will publish the certificate and its scope here when it is issued rather than announcing an intention to seek it.

We would rather lose a tender at the qualification stage than win it on an implication we cannot support at audit.

3. Framework alignment

Our delivery methodology is aligned to established public standards, which means a client can predict how an engagement will be run and can map our outputs onto their own control framework.

  • Engagement methodology aligned to the OWASP Testing Guide and the Penetration Testing Execution Standard.
  • Incident response methodology aligned to NIST SP 800-61 and the NIST Cybersecurity Framework.
  • Compliance readiness services delivered against ISO/IEC 27001, SOC 2, PCI DSS, and HIPAA control sets.

Alignment describes methodology, not certification. The distinction is set out in section 2.

4. Jurisdictional coverage

We deliver engagements to clients in the United Kingdom, the European Union, the United States, South Africa, and India, and we apply the data protection regime of the jurisdiction in which the affected individuals are located rather than asking international clients to accept Indian law by default.

  • United Kingdom — UK General Data Protection Regulation (UK GDPR); Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Supervisory authority: Information Commissioner's Office (ICO).
  • European Union and European Economic Area — Regulation (EU) 2016/679 (EU GDPR); The national data protection legislation implementing and supplementing the GDPR in the Member State in which the data subject is located. Supervisory authority: The supervisory authority of the EU or EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement — your choice, under Article 77 of the EU GDPR.
  • United States — California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.) and the CCPA Regulations; The comprehensive consumer privacy statutes in effect in twenty states as at the effective date of this notice, and those enacted and not yet in force; Sectoral federal law where applicable to an engagement, including HIPAA for protected health information and the GLBA Safeguards Rule for financial institutions; State data breach notification statutes in all fifty states. Supervisory authority: There is no single federal privacy authority. For CCPA matters, the California Privacy Protection Agency and the California Attorney General; for other state statutes, the Attorney General of the relevant state; and the Federal Trade Commission in respect of unfair or deceptive practices.
  • South Africa — Protection of Personal Information Act 4 of 2013 (POPIA). Supervisory authority: Information Regulator (South Africa).
  • India — Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 and commencing in phases, with most substantive obligations operative from 13 May 2027. Supervisory authority: Data Protection Board of India, currently being constituted under the Act. Until it publishes a channel for complaints, concerns should be addressed to us using the contact details on this page..

We are established in India and do not hold a UK or EU adequacy position. Our transfer mechanisms are set out in full in the Privacy Notice and the Data Processing Agreement, together with binding government and law enforcement access commitments mirroring Clauses 14 and 15 of the EU Standard Contractual Clauses — the material a transfer impact assessment actually turns on.

5. Security posture of this website and our client-facing systems

Described by category. Implementation detail, configuration values, and control parameters are supplied under a non-disclosure agreement, because publishing them would assist an attacker without improving your assessment.

  • Encrypted transport, enforced. Connections are encrypted and transport security is required rather than merely offered.
  • No public path to stored data. Our datastore denies client-side access by default; all reads and writes occur server-side through a credentialled service identity under least privilege.
  • Input validation on every submission path, with strict typing and bounded field lengths.
  • Automated abuse prevention on public endpoints, including rate limiting and automated-submission detection.
  • Request origin verification on state-changing operations.
  • Hardened browser security posture, including a content security policy, framing and content-type protections, and a permissions policy denying camera, microphone, and location access.
  • Restrained logging. Error output is sanitised and public responses carry no internal record identifiers.
  • No third-party tracking whatsoever. No analytics, advertising, or profiling cookies, and no third-party analytics or advertising scripts. This removes an entire category of data leakage rather than managing it.
  • Accessibility. Motion respects the operating system reduced-motion preference, and content remains readable without JavaScript.

6. Data protection documents

All four documents are published in full and are internally consistent: each reads its commitments from a single source, so a period or a deadline stated in one cannot contradict another.

7. Financial sector and regulated clients

Where you are a financial entity in scope of Regulation (EU) 2022/2554 (DORA), we will enter into a contractual annex addressing the elements required by Article 30(2): a complete description of the services and any subcontracting, the locations in which services are provided and data is processed with advance notice of change, provisions on availability, authenticity, integrity and confidentiality, provisions on access, recovery and return of data, service level descriptions, incident assistance, cooperation with your competent and resolution authorities, termination rights and notice periods, and participation in your resilience training.

Where the service supports a critical or important function, we will additionally address Article 30(3), including quantitative performance targets, unrestricted audit and inspection rights, participation in threat-led penetration testing, and an exit strategy with a defined transition period.

For US regulated clients we support the equivalent obligations: a Business Associate Agreement and Security Rule safeguards where an engagement touches protected health information under HIPAA; service provider oversight evidence under § 314.4(f) of the GLBA Safeguards Rule; third party service provider representations under § 500.11 of 23 NYCRR Part 500 for New York covered entities; and, for SEC registrants, prioritised factual findings during an incident so that a materiality determination can be made and documented inside the four-business-day window Item 1.05 of Form 8-K allows.

We will not assert that a standard agreement discharges a sector-specific regulatory requirement. Where an annex is required, we produce one.

8. Essential and important entities: NIS2

Article 21(2)(d) of Directive (EU) 2022/2555 makes the security of your relationships with direct suppliers your own regulatory obligation, and Article 21(3) requires you to account for each supplier's specific vulnerabilities and practices rather than relying on a generic questionnaire.

We support that obligation directly: our sub-processor assessment records, personnel confidentiality undertakings, engagement authorisation procedures, and the detailed technical and organisational measures documentation are all available to you as supplier assurance evidence.

9. How we authorise engagements

Offensive security work is lawful only with authorisation, and the authorisation has to be real rather than assumed. This is the control that protects both parties.

  • We require written confirmation that you own the in-scope assets or are authorised to permit testing of them, before any testing activity begins.
  • We require the assets, permitted techniques, and testing window to be identified and agreed in writing.
  • We operate to documented rules of engagement with defined control points and escalation routes.
  • We will decline an engagement where authorisation cannot be established, including where a third party controls the target infrastructure and has not consented.
  • We will refuse or pause an instruction that would require unlawful processing, and say so in writing rather than proceeding and recording an objection afterwards.

10. Reporting a security issue to us

If you believe you have found a vulnerability in this website or an issue affecting our services, write to security@zerorisklabs.com with the subject line "Security Incident". We acknowledge reports within 72 hours and will keep you informed of remediation progress.

Please give us a reasonable opportunity to remediate before any public disclosure. We will not pursue action against a reporter who acts in good faith, avoids privacy violations and service degradation, and does not access or modify data beyond what is necessary to demonstrate the issue. The responsible disclosure provisions in our Terms and Conditions apply.

11. Material available on request

The following is provided to clients and prospective clients under a non-disclosure agreement. It is withheld from this page because it contains implementation detail that would be useful to an attacker, not because it is unavailable to you.

  • Executed Data Processing Agreement, countersigned, including the Standard Contractual Clauses or International Data Transfer Agreement applicable to your jurisdiction.
  • CCPA service provider addendum, and state-specific privacy addenda where your state statute requires different terms.
  • Business Associate Agreement where an engagement involves protected health information under HIPAA.
  • Transfer impact assessment or transfer risk assessment documentation for the corridor relevant to your transfer.
  • Specific processing regions and data residency confirmation for your engagement.
  • Detailed technical and organisational measures, including control implementation detail withheld from public pages for security reasons.
  • Security questionnaire responses, including CAIQ-format and client-specific questionnaires.
  • Contractual annex addressing Article 30 of Regulation (EU) 2022/2554 (DORA) for financial-sector clients.
  • Supplier assurance documentation supporting Article 21(2)(d) of Directive (EU) 2022/2555 (NIS2) supply chain obligations.
  • Service provider oversight evidence for the GLBA Safeguards Rule and 23 NYCRR Part 500 where applicable.
  • Personnel confidentiality undertakings, engagement authorisation records, and rules of engagement templates.

We aim to return completed due diligence material within 5 business days of receiving a signed non-disclosure agreement.

12. Commitments about how we communicate

These are the standards we hold ourselves to in a market where security marketing is frequently unreliable.

  • We do not claim certifications, accreditations, or memberships we do not hold.
  • We do not publish client names, logos, or engagement details without written authorisation.
  • We do not publish performance statistics we cannot substantiate on request.
  • We tell you at qualification stage, not at contract stage, if we cannot meet a mandatory requirement in your tender.
  • We state deadlines as defined periods rather than as what is 'reasonable', so that a missed commitment is visible.

Contact for due diligence

For security questionnaires, contractual annexes, transfer documentation, or any other assurance material, contact us using the subject line below. Tell us your jurisdiction and your regulatory context so that we send the right documents first time.

ZeroRisk Labs

Ambari, Guwahati, Assam 781001, India

Email: privacy@zerorisklabs.com

Please use the subject line Vendor Due Diligence so your message is routed correctly on arrival.