What we promise, in writing.
Hosting, availability, disclosure and the frameworks we map to. If it is not on this page, ask and we will put it here.
Hosting and data residency
Zero Door SaaS is operated by Zerone on OVHcloud infrastructure inside the European Union; the target region is Paris. The exact data centre is stated in your order form.
Servers are inside the EU. Transfers from Türkiye to the EU are international transfers under KVKK and are covered by the Board standard contracts.
Self-hosted and air-gapped editions keep all data where you run them.
Availability and incident notice
- Monthly availability 99.5%, the same on every tier.
- Customer breach notice within 48 hours, on every tier.
- Liability cap: fees paid in the last 12 months; twice that for data protection.
Service status
There is no public status page yet. Incidents and maintenance windows are announced by e-mail to the technical contact on the order form.
Frameworks we map to
- PCI DSS 4.0
- HIPAA
- ISO 27001:2022
- SOC 2
- NIST 800-53
- FedRAMP
- GDPR
- NATO STANAG
- SOX ITGC
- NIST 800-171 / CMMC L2
- NERC CIP
- KVKK and Law 7545
Mapping means the audit trail and reports are organised by these controls. It does not mean Zerone holds a certificate for each framework; certifications are listed here when obtained.
Vulnerability disclosure
Report vulnerabilities to security@zeronesecurity.com. We acknowledge within two working days and do not pursue good-faith researchers. The full policy and safe-harbour terms are in the legal texts.
Sub-processors
The sub-processor list is published after the standard contracts are registered with the Personal Data Protection Board. Until then it is provided on request to customers under NDA.