Security and privacy you can verify.
Employers see wellbeing trends, never individuals, and only when at least 5 people are in a group.
The data promise
What employers can and can't see
What your employer sees
- Aggregated wellbeing trends
- Team-level ZenScore and Zenergy movement
- Participation rates
What they never see
- Any individual's score or answers
- Who used what
- Anyone in a group smaller than 5
The 5-person rule
No one can be singled out
No employer-facing view is ever shown for fewer than 5 people. On top of that, complementary suppression hides a group whenever it could be worked out by subtracting other groups, so an individual can never be identified indirectly.
Confidential by design
Individual answers are never exposed. Leaders only ever see aggregated, suppressed trends.
Your data stays in the UK
Hosted in the United Kingdom, encrypted in transit and at rest.
You control your data
UK GDPR data-subject rights are honoured, and a Data Processing Agreement is available.
Security controls
Our controls, mapped to ISO 27001
We are not certified to ISO 27001, but we operate a documented set of controls and policies, mapped to the standard's four themes.
| Annex A | Control | What we do | Status |
|---|---|---|---|
| Organizational (A.5) | |||
| A.5.1 | Policies for information security | Documented information security policy set, owner-approved, reviewed annually | In place |
| A.5.9 | Inventory of information and assets | Asset register maintained and classified | In place |
| A.5.12 | Classification of information | Four-level scheme: Public, Internal, Confidential, Restricted | In place |
| A.5.14 | Information transfer | TLS in transit, including the database | In place |
| A.5.15 | Access control | Role-based access, least privilege | In place |
| A.5.16 | Identity management | Verified identities via a managed identity provider | In place |
| A.5.19 | Supplier relationships | Signed data-processing agreements with sub-processors | In place |
| A.5.23 | Cloud services security | Established cloud provider, UK region, managed as code | In place |
| A.5.24 | Information security incident management | Documented incident-response runbook with a 72-hour breach-assessment process | In place |
| A.5.29 | Business continuity | Documented business continuity and disaster-recovery plan | In place |
| A.5.31 | Legal & regulatory | Registered with the ICO; UK GDPR aligned | In place |
| A.5.34 | Privacy & PII protection | 5-person cohort suppression, complementary suppression, and a DPIA for wellbeing data | In place |
| People (A.6) | |||
| A.6.6 | Confidentiality / NDAs | Signed by staff and contractors | In place |
| Physical (A.7) | |||
| A.7 | Data-centre security | Inherited from our cloud provider | In place |
| Technological (A.8) | |||
| A.8.3 | Information access restriction | Workspace scoping + 5-person gate | In place |
| A.8.5 | Secure authentication | SSO, pinned JWT verification, server-side sessions | In place |
| A.8.8 | Vulnerability management | Automated dependency & code scanning on every change | In place |
| A.8.9 | Configuration management | Infrastructure as code | In place |
| A.8.13 | Information backup | Automated backups + point-in-time recovery | In place |
| A.8.15 | Logging & monitoring | Structured logs, redaction, alerting | In place |
| A.8.20 | Network security | Private database, firewalls, TLS | In place |
| A.8.24 | Cryptography | AES-256, TLS, managed keys | In place |
| A.8.28 | Secure coding | 39 automated lint checks, peer review, CI | In place |
| A.8.32 | Change management | Pull-request review + CI on every change | In place |
Responsible disclosure
Found a security issue? Please tell us. We welcome good-faith research and will not pursue action against researchers who follow this policy.
- Email security@zenplus.health
- Machine-readable policy at /.well-known/security.txt
- Please allow us reasonable time to remediate before disclosure
Documents
A Data Processing Agreement is available to business customers.
Request our DPA View our sub-processor listQuestions about security or privacy?
Happy to walk your security and legal teams through any of the above, complete a questionnaire, or share our DPA.