Security & trust
This page is maintained by Procapita Management Consulting Group to answer common security questions about Zenithr Perform. It describes enabled platform controls today — it is not an independent certification.
Identity & access
Enterprise SSO on request
SAML/OIDC enterprise SSO available on request.
Role-based access
Granular roles per workspace and company — least privilege by default.
Tenant isolation
Every record is scoped to a workspace and company; cross-tenant reads are blocked at the database layer.
Data protection
Encryption in transit & at rest
TLS in transit, AES-256 at rest, managed keys.
Row-level security
Server-enforced access rules — not client-side checks.
Least-privilege backend
App services run with scoped credentials; admin operations are isolated and audited.
Operations
Monitoring
Continuous monitoring with on-call alerting for production incidents.
Immutable audit log
Every change to a record is captured — appraisals, calibration, configuration.
Incident response
Documented runbooks. Report security concerns to compliance@pro-capita.com.
Customer controls
Branding & domain
Customers control workspace branding and visible labels.
Export your data
CSV exports across cycles, scores, and audit.
Deletion on request
Data deletion honored under our DPA timelines.
Shared responsibility. Procapita operates the platform, runs the security controls described above, and maintains certifications under the ISO management systems below. Customers are responsible for their workspace configuration — role assignments, data they upload, retention and export decisions.