Trust

Security & trust

This page is maintained by Procapita Management Consulting Group to answer common security questions about Zenithr Perform. It describes enabled platform controls today — it is not an independent certification.

Identity & access

Enterprise SSO on request

SAML/OIDC enterprise SSO available on request.

Role-based access

Granular roles per workspace and company — least privilege by default.

Tenant isolation

Every record is scoped to a workspace and company; cross-tenant reads are blocked at the database layer.

Data protection

Encryption in transit & at rest

TLS in transit, AES-256 at rest, managed keys.

Row-level security

Server-enforced access rules — not client-side checks.

Least-privilege backend

App services run with scoped credentials; admin operations are isolated and audited.

Operations

Monitoring

Continuous monitoring with on-call alerting for production incidents.

Immutable audit log

Every change to a record is captured — appraisals, calibration, configuration.

Incident response

Documented runbooks. Report security concerns to compliance@pro-capita.com.

Customer controls

Branding & domain

Customers control workspace branding and visible labels.

Export your data

CSV exports across cycles, scores, and audit.

Deletion on request

Data deletion honored under our DPA timelines.

Shared responsibility. Procapita operates the platform, runs the security controls described above, and maintains certifications under the ISO management systems below. Customers are responsible for their workspace configuration — role assignments, data they upload, retention and export decisions.