COMPLIANCE

ZENDEV Strategy is a firm believer in cybersecurity and holds the following certifications through its software providers:


Certifications

IS 642819 and ISO/IEC 27001

ISO/IEC 27001 is one of the most widely recognized independent international security standards. This certificate is awarded to organizations that comply with ISO's high global standards. We have earned ISO/IEC 27001:2013 certification through software providers for Applications, Systems, People, Technology, and Processes.

Applicable to - All cloud services and on-premise products of our software, ManageEngine, Site24x7, WebNMS and GSP Solution.


PM 732705 and ISO/IEC 27701

ISO/IEC 27701 is an extension to the ISO/IEC 27001 and ISO/IEC 27002 standards for privacy management within the context of the organization. The certification standard is designed to enhance the existing Information Security Management System (ISMS) with additional requirements in order to establish, implement, maintain, and continually improve a Privacy Information Management System (PIMS). This standard enables organizations to demonstrate compliance with the various privacy regulations around the world that are applicable to them.

Applicable to - All business units, cloud services and on-premise products of our software, ManageEngine, Site24x7, WebNMS which function in the capacity of a PII controller and/or as a PII Processor.


CLOUD 714132 and ISO/IEC 27017

ISO/IEC 27017 gives guidelines for information security controls applicable to the provision and use of cloud services by providing additional implementation guidance for relevant controls specified in ISO/IEC 27002 and additional controls with implementation guidance that specifically relate to cloud services.

Zoho is certified with ISO/IEC 27017:2015 - Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services.

Applicable to - All Cloud services of our software, Manage Engine and Site24x7 .


PII 714133 and ISO/IEC 27018

ISO/IEC 27018 establishes commonly accepted control objectives, controls and guidelines for implementing measures on safeguarding the PII that is processed in a public cloud. These controls are an extension of ISO/IEC 27001 and ISO/IEC 27002, ISO/IEC 27018 which provide guidance to organizations concerned about how their cloud providers are handing personally identifiable information (PII).

Applicable to - All Cloud services of our software, Manage Engine and Site24x7.


FS 724104 and ISO 9001

ISO 9001 is defined as the international standard that specifies requirements for a Quality Management System (QMS). Organizations use the standard to demonstrate the ability to consistently provide quality products and services that meet customer and regulatory requirements. Desk, HRMS and Finance suite of our applications comply with ISO 9001 requirements.

Applicable to - Desk, HRMS products (i.e.) People, Payroll and Finance Plus products (i.e.) Books, Invoice, Inventory, Subscriptions, Expense, and Checkout.

ISO/IEC 20000 is the leading international IT Service Management System (SMS) standard, with the objective to ensure the quality of the IT services. It specifies requirements for an organization to establish, implement, maintain and continually improve a service management system and it supports the management of the service lifecycle, including the planning, design, transition, delivery and improvement of services to meet the service requirements and deliver value.

Applicable to - Network Operations Center (NOC) and Data Center (DC) Operations of our software providers.


SOC 2

Our software providers are SOC 2 Type II compliant. SOC 2 is an evaluation of the design and operating effectiveness of controls that meet the AICPA's Trust Services Principles criteria.

Applicable to - All cloud services and on-premise products of our software, ManageEngine, Site24x7, WebNMS and GSP Solution


SOC 2 + HIPAA

SOC 2 + HIPAA - An independent third-party audit firm has examined the description of the system related to Application Development, Production Support and the related General Information Technology Controls for the services provided to customers, from our software offshore development centre, based on SecurityPrivacy and breach requirements set forth in the Health Insurance Portability and Accountability Act (“HIPAA”) Administrative Simplification. The responsibility of ZenDev is limited to the extent it acts as a 'Business Associate'.

Applicable to - CRM, Desk, Mail, Creator, Projects, Workdrive (including Writer, Sheet, and Show), Sign, People, Books, Invoice, Inventory, Subscriptions, Expense, Checkout, Payroll, ManageEngine Desktop Central and ManageEngine ServiceDesk Plus Cloud.


CSA STAR Self-Assessment

The Cloud Security Alliance is a non-profit organization formed to define and raise awareness of best practices to help ensure a secure cloud computing environment and to help potential cloud customers make informed decisions when transitioning their IT operations to the cloud.The Consensus Assessments Initiative Questionnaire(CAIQ) is submitted by the cloud providers to document compliance with the Cloud Controls Matrix (CCM) and helps cloud service customers to assess the security capabilities and practices of a cloud service provider.

Zoho has done a Self-Assessment for the cloud services. Download the CSA STAR Self-Assessment from CSA STAR Registry for Zoho Corporation Pvt Ltd

Applicable to- All Cloud services of Zoho and ManageEngine.


PCI

Payment card industry (PCI) compliance refers to the technical and operational standards that businesses must follow to ensure that credit card data provided by cardholders is protected. PCI compliance is enforced by the PCI Standards Council, to ensure that all businesses that store, process or transmit credit card data electronically do so in a secure manner that helps reduce the likelihood that cardholders would have sensitive financial data stolen.

our software providers,, being PCI compliant, consistently adheres to a set of guidelines set forth by companies that issue credit cards.

Applicable to- All the finance Plus products (i.e.) Books, Invoice, Inventory, Subscriptions, Expense, Checkout and Commerce


GDPR

GDPR is a pan-European regulation that requires businesses to protect the personal data and privacy of EU citizens for processing of their personal data.

Our software providers have always demonstrated its commitment to its user's data privacy by consistently exceeding industry standards. ZenDev welcomes GDPR as a strengthening force of the privacy-consciousness that already exists in it. 

ZenDev’s offerings have privacy features that comply to GDPR, and Out software provider's processing of its customer's data adheres to the data protection principles of the GDPR. To know more about how ZenDev and Zoho complies with GDPR, click here.   


CCPA

CCPA is a data privacy law specific to the processing of personal information of California residents that requires businesses to protect their personal information and provides privacy.

ZenDev has always demonstrated its commitment to its user's data privacy by consistently exceeding industry standards. ZenDev welcomes CCPA as a strengthening force of the privacy-consciousness that already exists in it.

Our software provider's offerings have privacy features that enable its users to comply with the CCPA, and Zoho's processing of its Californian customer's data adheres to requirements of the CCPA. To know more about this, click here.   


TRUSTe

TRUSTe Review ZenDev is proud to state that Zoho’s privacy policy, platform, website, and support portal have been reviewed by TRUSTe for compliance with their program requirements. 

ZenDev is proud to state that Zoho Corporation is certified to be compliant with the SWISS-U.S. PRIVACY SHIELD FRAMEWORK


CSA

Certified Senders Alliance (CSA) is a quality certification for mailbox service providers like Zoho Campaigns, making them enter the league of trusted senders. Zoho Campaigns is a CSA-certified service, giving you higher email open rates, improvement in deliverability with white listed IPs, and protection against any legal risk.

Applicable to - Campaigns


Signal spam

Signal spam reports help in providing FBL data, primarily technical information for identification of spammers and marketing abuse, from major ISPs like Orange.fr, SFR.fr, and so on. It has many spam reporting plugins for third-party browsers and email clients, focused at the French communities worldwide. It’s important for ZenDev, Zoho corporation, and our customers to know all the recipients who mark or report the emails they receive as ‘spam’, so that we can remove them from the lists. Hence, this certification protects our network reputation in the French region.  Applicable to - Zoho Corporation