Legal
OverviewTerms of ServiceAcceptable Use PolicyAI TermsPrivacy PolicyRefund PolicyData Processing AddendumSub-processorsService Level AgreementCookies StatementData Act AddendumGDPR ComplianceISO ComplianceBourbon Science Inc.
ISO 27001 v2022: COMPLIANT.
Zoko recognises that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of our business and to the privacy of our partners. Bourbon Science Inc., trading as Zoko, operates an information security management system aligned to ISO 27001 v2022, the international standard for managing information security. It covers data security, network security, application security, endpoint security, and corporate security, and is monitored continuously. Its controls include encryption of data at rest and in transit, role-based access on a least-privilege basis with multi-factor authentication for administrative access, logging and monitoring of production systems, vulnerability management and patching, secure development and change management, backup and disaster recovery, personnel screening and security training, and a documented incident response process. The same system underpins the security commitments in our Data Processing Addendum, the availability commitment in our Service Level Agreement, and the security section of our Privacy Policy.
All the details are in the Zoko Trust Center. That is where we publish our current compliance status against ISO 27001 and the GDPR, the controls behind it, our full set of information security policies and procedures, and the documents available on request, including our ISMS Manual, ISMS Scope Document, and information security roles and responsibilities.
For security or diligence questions, to request a document that is not publicly viewable, or to report a vulnerability, write to contact@zoko.io with the subject line "Security".