Trust Centre

Security and privacy you can verify.

Employers see wellbeing trends, never individuals, and only when at least 5 people are in a group.

UK-hosted
Encrypted
Independently code-audited
Data residency
United Kingdom
Encryption
TLS + AES-256
Access
Role-based + SSO
Privacy
5-person suppression
AI
First-party model
Compliance
UK GDPR + DPA

The data promise

What employers can and can't see

What your employer sees

  • Aggregated wellbeing trends
  • Team-level ZenScore and Zenergy movement
  • Participation rates

What they never see

  • Any individual's score or answers
  • Who used what
  • Anyone in a group smaller than 5
5
minimum group size

The 5-person rule

No one can be singled out

No employer-facing view is ever shown for fewer than 5 people. On top of that, complementary suppression hides a group whenever it could be worked out by subtracting other groups, so an individual can never be identified indirectly.

Confidential by design

Individual answers are never exposed. Leaders only ever see aggregated, suppressed trends.

Your data stays in the UK

Hosted in the United Kingdom, encrypted in transit and at rest.

You control your data

UK GDPR data-subject rights are honoured, and a Data Processing Agreement is available.

Security controls

Our controls, mapped to ISO 27001

We are not certified to ISO 27001, but we operate a documented set of controls and policies, mapped to the standard's four themes.

Annex A Control What we do Status
Organizational (A.5)
A.5.1 Policies for information security Documented information security policy set, owner-approved, reviewed annually In place
A.5.9 Inventory of information and assets Asset register maintained and classified In place
A.5.12 Classification of information Four-level scheme: Public, Internal, Confidential, Restricted In place
A.5.14 Information transfer TLS in transit, including the database In place
A.5.15 Access control Role-based access, least privilege In place
A.5.16 Identity management Verified identities via a managed identity provider In place
A.5.19 Supplier relationships Signed data-processing agreements with sub-processors In place
A.5.23 Cloud services security Established cloud provider, UK region, managed as code In place
A.5.24 Information security incident management Documented incident-response runbook with a 72-hour breach-assessment process In place
A.5.29 Business continuity Documented business continuity and disaster-recovery plan In place
A.5.31 Legal & regulatory Registered with the ICO; UK GDPR aligned In place
A.5.34 Privacy & PII protection 5-person cohort suppression, complementary suppression, and a DPIA for wellbeing data In place
People (A.6)
A.6.6 Confidentiality / NDAs Signed by staff and contractors In place
Physical (A.7)
A.7 Data-centre security Inherited from our cloud provider In place
Technological (A.8)
A.8.3 Information access restriction Workspace scoping + 5-person gate In place
A.8.5 Secure authentication SSO, pinned JWT verification, server-side sessions In place
A.8.8 Vulnerability management Automated dependency & code scanning on every change In place
A.8.9 Configuration management Infrastructure as code In place
A.8.13 Information backup Automated backups + point-in-time recovery In place
A.8.15 Logging & monitoring Structured logs, redaction, alerting In place
A.8.20 Network security Private database, firewalls, TLS In place
A.8.24 Cryptography AES-256, TLS, managed keys In place
A.8.28 Secure coding 39 automated lint checks, peer review, CI In place
A.8.32 Change management Pull-request review + CI on every change In place

Responsible disclosure

Found a security issue? Please tell us. We welcome good-faith research and will not pursue action against researchers who follow this policy.

Documents

A Data Processing Agreement is available to business customers.

Request our DPA View our sub-processor list

Questions about security or privacy?

Happy to walk your security and legal teams through any of the above, complete a questionnaire, or share our DPA.