Trusted by Design

Security & Compliancebacked by Zscaler

Velocity Cyber partners inherit the trust of the Zscaler Zero Trust Exchange — independently audited against 30+ internationally recognized government and commercial standards so your customers and prospects can adopt with confidence.

Zscaler Compliance Portal

150+

Global Data Centers

11

Sovereign Cloud Regions

34

Active Certifications

100%

Continuous Audit Coverage

Global Security & Quality

Independently audited against the most widely recognized international security, quality, and privacy standards.

Global

SOC 2 Type 2

Audited controls for security, availability, and confidentiality.

View report
Global

SOC 3

Public trust report for general-use security assurance.

View report
Global

ISO/IEC 27001

Information security management system standard.

View report
Global

ISO/IEC 27017:2015

Cloud-specific information security controls.

View report
Global

ISO/IEC 27018:2019

Protection of personal data in the public cloud.

View report
Global

ISO 22301

Business continuity management system certification.

View report
Global

ISO/IEC 27701

Privacy information management extended.

View report
Global

CSA STAR Level 2

Cloud Security Alliance Security Trust Assurance Registry.

View report
Global

HITRUST

Common Security Framework for healthcare data.

View report
Global

CyberVadis Gold

Independent cyber risk rating at the highest tier.

View report
Global

TruSight

Multi-party assessment for vendor risk validation.

View report
US

CISA Secure-by-Design Pledge

Commitment to secure-by-design product development.

View report

Data Protection & Privacy

Encryption, data privacy, and cross-border data transfer protections mandated by modern regulations.

EU

GDPR

General Data Protection Regulation compliance.

View report
US

HIPAA

Protected health information safeguards for healthcare.

View report
Global

PCI DSS

Payment Card Industry Data Security Standard.

View report
US

FIPS 140-2

Federal Information Processing cryptographic validation.

View report
US

FIPS 140-3

Latest cryptographic module security standard.

View report
EU/US

EU-US Data Privacy Framework

Validated transatlantic personal data transfers.

View report
Swiss/US

Swiss-US Data Privacy Framework

Switzerland to US personal data transfer framework.

View report
UK/US

UK Extension to EU-US DPF

Extends DPF coverage to UK transfers.

View report

Government & Sovereign Cloud

Certified for the most demanding government, defense, and regulated-industry cloud environments worldwide.

US

NIST 800-53 Rev. 5

Security and privacy controls for federal systems.

View report
Australia

IRAP

Information Security Registered Assessors Program assessment.

View report
Australia

ACN

Australian Cyber Security Centre certified cloud.

View report
Canada

CCCS - CSP ITS

Canadian Centre for Cyber Security cloud assessment.

View report
Singapore

MTCS Level 3

Multi-Tier Cloud Security, highest tier.

View report
Japan

ISMAP

Information System Management and Assessment Program.

View report
Spain

ENS

Esquema Nacional de Seguridad government framework.

View report
Germany

C5

BSI Cloud Computing Compliance Controls Catalog.

View report
Germany

TISAX

Automotive industry information security assessment.

View report
Singapore

CPSTIC Prod Med

Cloud Provider Security Test & Inspection Criteria.

View report
UK

G-Cloud

UK government digital marketplace framework.

View report
UK

Cyber Essentials Plus

NCSC-backed baseline cyber hygiene certification.

View report
Denmark

DCSO Security Assessment

Danish municipal cloud security assessment.

View report
UK

FSQS

Financial Services Qualification System for UK finance.

View report
Vendor Onboarding Pack

Trust documentation, on demand

Pre-built security and procurement documentation accelerates your customer due diligence — MSP partners can share audit-ready artifacts without escalating every deal.

Subprocessors

Full list of organizations that process customer data on Zscaler's behalf, with regional scope and updated tracking.

Sensitive Data Handling Assessment

Detailed documentation of how sensitive data is classified, transmitted, stored, and destroyed across the platform.

Certificate of Insurance

Current proof of cyber liability and professional indemnity insurance coverage maintained by Zscaler.

SIG Lite

Standardized Information Gathering questionnaire response for efficient vendor security review.

Pass every security review

Win regulated deals faster with a vendor whose audit posture is already enterprise-grade. Get the full Velocity Cyber partner pack and we'll help you close your next compliance-gated opportunity.