Trust Centre
Trust Centre
Security and compliance are central to how Employee Zero works. This page summarises our approach for clients and prospects carrying out due diligence. More detailed evidence is available under NDA.
Certifications and registrations
Employee Zero holds, or is actively working towards, the following:
- Cyber Essentials — certified
- Cyber Essentials Plus — in progress (2026)
- ISO/IEC 27001 (information security management) — certification in progress (2026); statement of intent in place
- ISO/IEC 42001 (AI management systems) — certification in progress (2026); statement of intent in place
- Registered with the Information Commissioner’s Office (ICO) — registration number ZA424545
How we protect information
We operate an information security management system that covers, among other things:
- access control and least-privilege
- encryption of data in transit and at rest, and encrypted remote access to client systems
- secure credential management
- vulnerability and patch management
- endpoint protection and managed backup
- logging and monitoring of system access
- security training and background checks for staff with access to client data
Monitoring and incident response
We provide 24/7 monitoring and follow a defined incident-response process. Where we become aware of a security incident affecting a client, we notify the client and work with them to investigate and contain it, in line with our contractual commitments.
Data residency and sub-processors
We operate across the UK, the United States and Singapore. We maintain a single list of sub-processors, which includes Zendesk (support ticketing and Client Portal), NinjaOne (remote monitoring and management) and Cloudflare (hosting and content delivery), alongside the platform and security providers we use to deliver services. The current list is published in our Sub-processor List and referenced in our GDPR / Data Processing Addendum.
Business continuity and resilience
We maintain business-continuity and disaster-recovery plans for our own services and test them regularly. For financial-sector clients in scope of the EU Digital Operational Resilience Act (DORA), please see our DORA Statement.
Regulatory alignment
We track and align our practices to the regimes relevant to a managed service provider, including the UK Network and Information Systems Regulations 2018 and the Telecommunications (Security) Act 2021, and we monitor the EU Cyber Resilience Act and EU Data Act as they apply to our services. We are committed to the Bribery Act 2010 and the Modern Slavery Act 2015; our statement is available on request.
Security assurance for clients
We share security and compliance information with clients, and with prospects who are in an active procurement process with us, on a need-to-know basis and at our discretion. If you are working with us and need assurance materials for your due diligence, please ask your Employee Zero contact. We do not make our internal security documentation available on open request.
Reporting a security vulnerability
We welcome reports from security researchers and members of the public that help us keep our services safe.
If you believe you have found a security vulnerability in empzer.com or another Employee Zero service, please email security@empzer.com with enough detail for us to reproduce and assess the issue — for example the affected URL or system, a description of the vulnerability, and the steps to reproduce it. If you would like to encrypt your report, request our PGP key at the same address.
When investigating, please act in good faith and do not:
- access, modify or delete data that is not your own
- degrade, disrupt or overload our services (for example denial-of-service testing)
- use social engineering, phishing or physical attacks
- publicly disclose the issue before we have had a reasonable opportunity to fix it
What you can expect from us:
- we will acknowledge your report within [14] Business Days
- we will keep you updated on our assessment and progress
- we will work to remediate confirmed issues as quickly as is practical, prioritised by severity
- we will not pursue legal action against researchers who follow this process in good faith (safe harbour)
This process is for security vulnerability reports only. For privacy or data-protection concerns, please use our Complaints Procedure or contact privacy@empzer.com. We do not currently operate a paid bug-bounty programme.