Security & Compliance
Continuously audited. Compliance-ready by default.
Z2 maintains SOC 2 Type II, HIPAA, and FedRAMP Moderate certifications — with continuous control monitoring via Drata since 2021 — so procurement and security reviews move at the speed of engineering, not paperwork.
- SOC 2Type II
- HIPAAAligned
- FedRAMPModerate
- DrataContinuous Audit
Security Architecture
Six audit-ready controls, mapped to your questionnaire.
Each panel below corresponds to a row in the CAIQ, SIG Lite, or VSAQ your team will send. Reviewers find the answer without a sales call.
-
01
Data residency, by region
Customer workloads pin to US, EU, or APAC regions with isolated per-tenant namespaces. Cross-region replication is opt-in per workflow, never implicit. Region selection is enforced at the org level and visible in the audit log.
-
02
Encryption, in transit and at rest
TLS 1.3 for all data in motion. AES-256 at rest for workflow state, secrets, and connector payloads. Tenant-specific data keys are wrapped by a platform root key held in FIPS 140-2 Level 3 HSMs.
-
03
Customer-managed keys (BYOK)
Bring your own KMS keys via AWS KMS, GCP KMS, or HashiCorp Vault. Key rotation, revocation, and per-workflow scoping are first-class — a key disable stops workflow execution within 60 seconds across all regions.
-
04
Identity: SSO, SCIM, RBAC
SAML 2.0 and OIDC single sign-on with SCIM 2.0 provisioning. Role-based access control down to workflow, connector, and field level. Privileged actions require step-up MFA; session lifetime defaults to 8 hours.
-
05
Audit log export
Every administrative action, secret access, and workflow change is captured in an append-only audit log. Stream to Splunk, Snowflake, Datadog, or S3 via native connectors — retention configurable up to 7 years.
-
06
Incident response & disclosure
24/7 security operations with a published 1-hour acknowledgment SLA for customer-reported issues. CVEs in platform dependencies disclosed within 72 hours; customer-impacting incidents notified within 24 hours per contract.
By the numbers
The security operation, quantified.
- 1,400+ Continuous controls monitored in Drata
- 99.99% Platform uptime across 18 consecutive quarters
- AES-256 Encryption at rest, TLS 1.3 in transit
- < 1 biz day Median turnaround on SOC 2 report requests under NDA
Procurement FAQ
The five questions your security team will ask first.
Written for IT Security and Procurement reviewers. Send the page link in lieu of a first call when you need to move fast.
- How is tenant data isolated on the Z2 platform?
- Every customer workload runs in a dedicated Kubernetes namespace with a dedicated service account, network policy, and encrypted volume. Logical isolation is enforced by the runtime — there is no shared execution context between tenants, and cross-tenant calls fail closed at the control-plane layer.
- Is a signed BAA available for HIPAA workloads?
- Yes. Z2 signs a standard Business Associate Agreement for any customer processing PHI. The BAA, the SOC 2 Type II report, and our latest penetration-test summary are available under NDA via the Request Compliance Docs form on this page.
- How long are audit logs retained, and can we export them?
- Audit logs are retained for 13 months by default inside the platform and are exportable in real time to Splunk, Snowflake, Datadog, or an S3 bucket you control. Customer-managed retention can be extended to 7 years at no additional cost.
- How do we access the FedRAMP Moderate package?
- The full FedRAMP Moderate package — SSP, POA&M, continuous-monitoring artifacts, and the agency authorization letter — is available to qualified US public-sector and regulated-industry buyers. Submit a request through the form below; our compliance team responds within one business day with the secure-delivery workflow.
- What happens to our data when the contract ends?
- On contract termination, customer data is exported in full within 30 days, then cryptographically erased from primary, replica, and backup stores within an additional 30 days. We provide a signed certificate of destruction and retain deletion logs for 7 years to satisfy audit trails.
Compliance Documentation
Request the SOC 2 report, HIPAA BAA, and FedRAMP package.
Submit your details once. Most requests are fulfilled within one business day under NDA — no sales call required.
By submitting, you agree to Z2's privacy and security terms. Documents are delivered via secure link under mutual NDA.