Skip to content
Z2 Software Z2 Software v6.4 SOC 2 · HIPAA · FedRAMP

Security & Compliance

Continuously audited. Compliance-ready by default.

Z2 maintains SOC 2 Type II, HIPAA, and FedRAMP Moderate certifications — with continuous control monitoring via Drata since 2021 — so procurement and security reviews move at the speed of engineering, not paperwork.

  • SOC 2Type II
  • HIPAAAligned
  • FedRAMPModerate
  • DrataContinuous Audit

Security Architecture

Six audit-ready controls, mapped to your questionnaire.

Each panel below corresponds to a row in the CAIQ, SIG Lite, or VSAQ your team will send. Reviewers find the answer without a sales call.

  1. 01

    Data residency, by region

    Customer workloads pin to US, EU, or APAC regions with isolated per-tenant namespaces. Cross-region replication is opt-in per workflow, never implicit. Region selection is enforced at the org level and visible in the audit log.

  2. 02

    Encryption, in transit and at rest

    TLS 1.3 for all data in motion. AES-256 at rest for workflow state, secrets, and connector payloads. Tenant-specific data keys are wrapped by a platform root key held in FIPS 140-2 Level 3 HSMs.

  3. 03

    Customer-managed keys (BYOK)

    Bring your own KMS keys via AWS KMS, GCP KMS, or HashiCorp Vault. Key rotation, revocation, and per-workflow scoping are first-class — a key disable stops workflow execution within 60 seconds across all regions.

  4. 04

    Identity: SSO, SCIM, RBAC

    SAML 2.0 and OIDC single sign-on with SCIM 2.0 provisioning. Role-based access control down to workflow, connector, and field level. Privileged actions require step-up MFA; session lifetime defaults to 8 hours.

  5. 05

    Audit log export

    Every administrative action, secret access, and workflow change is captured in an append-only audit log. Stream to Splunk, Snowflake, Datadog, or S3 via native connectors — retention configurable up to 7 years.

  6. 06

    Incident response & disclosure

    24/7 security operations with a published 1-hour acknowledgment SLA for customer-reported issues. CVEs in platform dependencies disclosed within 72 hours; customer-impacting incidents notified within 24 hours per contract.

By the numbers

The security operation, quantified.

  • 1,400+ Continuous controls monitored in Drata
  • 99.99% Platform uptime across 18 consecutive quarters
  • AES-256 Encryption at rest, TLS 1.3 in transit
  • < 1 biz day Median turnaround on SOC 2 report requests under NDA

Procurement FAQ

The five questions your security team will ask first.

Written for IT Security and Procurement reviewers. Send the page link in lieu of a first call when you need to move fast.

How is tenant data isolated on the Z2 platform?
Every customer workload runs in a dedicated Kubernetes namespace with a dedicated service account, network policy, and encrypted volume. Logical isolation is enforced by the runtime — there is no shared execution context between tenants, and cross-tenant calls fail closed at the control-plane layer.
Is a signed BAA available for HIPAA workloads?
Yes. Z2 signs a standard Business Associate Agreement for any customer processing PHI. The BAA, the SOC 2 Type II report, and our latest penetration-test summary are available under NDA via the Request Compliance Docs form on this page.
How long are audit logs retained, and can we export them?
Audit logs are retained for 13 months by default inside the platform and are exportable in real time to Splunk, Snowflake, Datadog, or an S3 bucket you control. Customer-managed retention can be extended to 7 years at no additional cost.
How do we access the FedRAMP Moderate package?
The full FedRAMP Moderate package — SSP, POA&M, continuous-monitoring artifacts, and the agency authorization letter — is available to qualified US public-sector and regulated-industry buyers. Submit a request through the form below; our compliance team responds within one business day with the secure-delivery workflow.
What happens to our data when the contract ends?
On contract termination, customer data is exported in full within 30 days, then cryptographically erased from primary, replica, and backup stores within an additional 30 days. We provide a signed certificate of destruction and retain deletion logs for 7 years to satisfy audit trails.

Compliance Documentation

Request the SOC 2 report, HIPAA BAA, and FedRAMP package.

Submit your details once. Most requests are fulfilled within one business day under NDA — no sales call required.

By submitting, you agree to Z2's privacy and security terms. Documents are delivered via secure link under mutual NDA.