Security at ZOQENA.
How ZOQENA controls access to vendor compliance information, protects private documents, and secures connected workflows.
Security Model
Access should follow the relationship.
ZOQENA connects organizations, vendors, projects, requirements, documents, and compliance records. Access to that information is scoped to the authorized user and the relevant relationship rather than treated as one shared pool of data.
Controlled application access
Protected application areas require authenticated access. Public marketing pages, free tools, and authorized time-limited guest correction workflows are deliberate exceptions.
Organization-scoped authorization
Access to vendors, projects, requirements, and compliance records is evaluated within the user's organization and authorized role.
Private document handling
Vendor documents and sensitive credential information are kept out of public pages and restricted to authorized workflows and relationships.
Privacy-safe public Passport
Public Passport views expose only limited, non-sensitive summary information. Raw documents and sensitive identifiers are not intended for public display.
Data Access
Organization and vendor information stays scoped.
Organization users are authorized within their organization context. Vendor-facing access is limited to the vendor's own information and the relationships made available to that vendor. Private records are not intended to become public simply because a vendor has a public Passport profile.
Sensitive information stays out of public Passport views.
Public-facing summaries are designed to exclude sensitive information such as raw uploaded documents, private document URLs, W-9 data, taxpayer identifiers, Social Security numbers, employer identification numbers, and insurance policy numbers.
Connected Workflows
Security controls extend beyond the login screen.
ZOQENA also applies controls to programmatic access, outbound integrations, and guest correction workflows.
Scoped API keys
Organization API keys are scoped to permitted read access, can be revoked, and are stored as hashes rather than retained as reusable plaintext secrets.
Signed webhooks
Webhook deliveries use request signing so receiving systems can validate authenticity. Outbound webhook handling also includes protections against unsafe destination requests.
Protected guest correction links
Guest correction workflows use high-entropy, time-limited tokens that can be revoked. The server stores a hash of the secret rather than the reusable token itself.
Review & Accountability
Sensitive decisions remain reviewable.
ZOQENA can extract credential information and evaluate it against configured requirements, but ambiguous information can be routed to manager review. Correction activity, responses, re-evaluation, and status history remain part of the compliance record rather than disappearing after an update.
Certifications
We don't claim certifications we haven't earned.
ZOQENA does not currently represent itself as SOC 2 or ISO 27001 certified. This page describes implemented product and access-control practices; it should not be interpreted as an independent security certification or audit attestation.
Have a security or data-handling question?
Contact ZOQENA with questions about access, vendor data, documents, API access, or other security-related topics.
Contact ZOQENA