Zediant Technologies logo
🛡️ SOC 2 Type II Audited | ⚖️ Global Regulatory Alignment | 🌏 APAC & EMEA Presence

SOC 2 Type II Audited

Security controls designed around recognised standards.

Zediant is a SOC 2 Type II audited company, which means our controls around security, availability, processing integrity, and confidentiality have been assessed according to trust service criteria during the audit period.

What this means for clients:

  • Security measures and control mechanisms
  • Procedures for controlled access and authorization
  • Protection of client data and intellectual property
  • Documented engineering and delivery processes
  • Controls intended to meet enterprise security needs

Security controls at a glance.

Data Protection

Encryption, secure data storage and access control on sensitive data.

Identity & Access

Role based access and least privilege approach.

Secure Development

Security incorporated in software development lifecycle.

Infrastructure Security

Controlled environment and security focused infrastructure practices.

Monitoring & Logging

Monitoring, logging and alerting to detect unusual activity and operation risk.

Backup & Recovery

Process designed to ensure availability and recovery of data.

Incident Response

Process to detect, respond and recover from security incidents.

Vendor & Third-Party Risk

Security around external tools and services used in delivery environments.

Our security framework.

Security is implemented throughout the software development life cycle, including the development process and the post-development phase, which includes deployment.

01

Data Protection

End-to-end encryption and access control protect the client's data and intellectual property at all stages of the process.

02

Secure Development Lifecycle

Security is engineered into the design, development, test, and deployment stages, as opposed to being an afterthought.

03

Identity & Access Management

Role-based access means that only people who are meant to have access get access.

04

Continuous Monitoring & Risk Management

Continual monitoring helps detect and prevent risks before they become problems.

05

Operational Integrity

Standardized and audited workflows ensure reliable delivery in all projects.

06

Compliance-Ready Engineering

Our workflow is designed to meet the compliance needs of our clients.

Illustration of a layered shield representing the six-part security framework

Client Environment Security

Controlled development environments.

Access to client environments is controlled according to project requirements, role responsibilities and security policies.

Role-Based Access
Least Privilege
Environment Separation
Credential Management
Access Review
Secure Remote Access

Supporting global privacy and data requirements.

Our engineering processes have been crafted to help our customers operate within different regulation systems. We take care of data protection, privacy, and data handling issues as part of architecture and delivery.

01

UK & Europe

GDPR and UK GDPR considerations

02

Australia

Australian Privacy Principles

03

UAE

UAE data protection requirements

Regulatory requirements depend on the application, the type of data, and the jurisdiction. We help our clients include these regulatory requirements in the design and implementation process.

How we handle client data.

It is only natural for enterprise customers to want to know what will happen to their data after a project is initiated. This is how we handle that.

Where Data Is Stored

The storage will be based on whether we have client-managed infrastructures, Zediant-managed infrastructures, or a combination of both, depending on the requirements of the engagement.

Who Can Access It

It is restricted to the engineering pod for the specific engagement and not the whole organization.

How Access Is Controlled

The access is through role-based, whereby the engineers can access systems and data that pertain to their roles.

Credential Management

Credentials are managed through a rotation process and not the usual one-time issue of credentials.

Production Access

The production environment sits at a higher tier of access control than the development and staging environments.

Development & Testing Data

Development and testing should, wherever possible, use anonymized data and not live client data.

Data Retention & Removal

Data for the project will be disposed of after a specified period following the end of the engagement.

Secure use of AI in software engineering.

AI-enabled development can improve engineering productivity, but it also presents new security and governance challenges. When we use AI tools, our engineers apply judgment and follow security protocols that we have in place to protect client code, data and intellectual property.

Careful AI Tool Usage

Engineers utilise AI tools with full knowledge of client confidentiality and the sensitivity of the project, following the same security protocols that we adhere to in the rest of our engineering process.

Protection of Client Data

Client code, credentials, and other sensitive information are not provided to the AI tool beyond the engineering scope.

AI Security

Human Engineering Oversight

The output from the AI is still reviewed through the usual engineering testing.

Secure Integration

AI assisted tools are integrated within development flows with the same security protocols that are followed in other parts of engineering.

Client code and confidential information are never shared with AI tools outside the controlled engineering environment.

Let's review your security requirements.

Have security, compliance or data protection requirements for an upcoming engineering engagement? Talk with our team about your environment, requirements and due-diligence process.

Talk to Our Security & Engineering Team

Reducing risk across the engineering lifecycle.

Protect Client Data

Security policies aimed at protecting sensitive information and intellectual property.

Control Access

Well-defined access and authorization policies reduce unnecessary exposure.

Improve Operational Resilience

Engineering and operational practices that contribute towards building reliable systems and controlled change.

Support Due Diligence

Documentation and security practices that aid clients in evaluating engineering risks.

Supporting your security & procurement process.

Security reviews are part of selecting the right engineering partner. We work with client security, procurement and technology teams to address requirements during due diligence.

01

Security Questionnaires

Support client-led security assessments.

02

Technical Reviews

Discuss architecture, environments and engineering controls.

03

Documentation

Provide relevant security and engineering documentation where applicable.

04

Ongoing Reviews

Support security requirements as the engagement evolves.

Need security or compliance documentation?

Security reviews always involve documentation - this may include anything from our SOC 2 Type II compliance overview to applicable policies. In order to avoid posting any sensitive material on our public web site, we make such documentation available to you directly.

What you can request

  • SOC 2 Type II alignment overview
  • Relevant security and engineering policies
  • Data handling and processing information
  • Answers to your security questionnaire
Request Security Documentation