Trust & Security
Every answer your
vendor form needs.
How we protect your data and your IP — ISO 27001:2022 certified, NDA-backed with IP assignment, and least-privilege access. Whether it's your bank's vendor form, your insurer's questionnaire, or your biggest client's security review — the answers are documented and shared on request.
Our Security Posture
The controls behind every engagement.
ISO 27001:2022 certified
Zedtreeo is operated by LegelpTech Outsourcing Pvt Ltd, an ISO 27001:2022 certified company. Information-security controls run across vetting, contracting, onboarding, and day-to-day delivery. Certificate details are disclosed on our compliance page.
GDPR-aware data handling
We respect EU data-subject rights throughout placement and engagement, apply data-minimisation, and can put Standard Contractual Clauses in place where personal data is involved.
NDAs & IP assignment
Every specialist signs an NDA before any access is granted. IP assignment is written into the master services agreement on every engagement — all work product belongs to your company.
Least-privilege access
Access is scoped to what each engagement requires, with unique logins, MFA, and no shared credentials. Access is provisioned at the start and revoked at offboarding.
Encryption & secure handling
Sensitive data is handled over encrypted channels and kept within approved systems. No company or client data on personal email or unmanaged cloud storage.
Vendor-form ready
We complete the security questionnaires your bank, insurer, or enterprise client sends, respond to security reviews, and provide onboarding documentation on request.
Running a vendor review? We complete security questionnaires and provide onboarding documentation on request. For full legal-entity and certification details, see our compliance page, or request a security review.
Asked for SOC 2? Here’s the honest answer.
We hold ISO 27001:2022 — not a SOC 2 report. The two cover the same ground.
SOC 2 is a US attestation framework; ISO 27001 is the international certification standard for the same discipline. Our operating company holds ISO 27001:2022, independently audited on a three-year certification cycle. If your vendor form asks for SOC 2, the table below maps each Trust Services area to the ISO 27001 controls we're certified against — most reviewers accept the certificate plus a completed questionnaire.
| SOC 2 Trust Services area | Covered under ISO 27001:2022 by |
|---|---|
| Security (common criteria) | Certified ISMS: risk assessment, access control, MFA, least-privilege provisioning |
| Confidentiality | NDAs before access, IP assignment in the MSA, data classification and handling rules |
| Availability | Business-continuity and incident-response procedures under the certified ISMS |
| Processing integrity | Change control and human review of AI-assisted output before delivery |
| Privacy | Data-minimisation, encrypted channels, approved-systems-only handling |
Security & Compliance FAQs
The questions vendor forms ask first.
Yes. Zedtreeo is operated by LegelpTech Outsourcing Pvt Ltd, which holds ISO 27001:2022 certification. The certificate is available on request and referenced on our compliance page.
You do. IP assignment is part of the master services agreement on every engagement, so all work created by a specialist belongs to your company.
Yes — every specialist signs an NDA before any materials or systems are shared, and confidentiality obligations continue beyond the engagement.
No. Zedtreeo, via its operating company LegelpTech Outsourcing Pvt Ltd, handles payroll, contracting, and compliance. You direct the work; we carry the employment relationship.
Yes. We complete vendor questionnaires and respond to security reviews as part of onboarding — whether it comes from your bank, insurer, or an enterprise client. Request one via our contact page.
No — our certification is ISO 27001:2022, the international equivalent covering the same control domains (access control, encryption, incident response, vendor management, business continuity). Most US vendor reviews accept ISO 27001 certification plus a completed questionnaire in place of a SOC 2 report. If SOC 2 is a hard requirement on your form, contact us and we’ll walk your reviewer through the control mapping.
Access is least-privilege and scoped to the engagement, with unique logins and MFA. It's provisioned at the start and revoked at offboarding.
Ready for a Security Review?
Send your vendor questionnaire or book a call — we'll complete procurement onboarding and get your team staffed. Free 5-day trial, no contracts.
Every savings claim on this site, in one table
Procurement asks what the alternative costs. This is the published answer, with the source next to each number — Bureau of Labor Statistics medians for the nearest US occupation, loaded 1.3× for employer cost. Click any occupation to check it on bls.gov rather than take our word for the gap.
| Role | US occupation (BLS median) | Loaded US cost/yr | Zedtreeo/yr | Saving |
|---|---|---|---|---|
| Full-Stack Developers | Software Developers SOC 15-1252 · $133,080 | $173,004 | $15,360 | 91% |
| WordPress Developers | Web Developers SOC 15-1254 · $90,930 | $118,209 | $9,600 | 92% |
| Accountants | Accountants and Auditors SOC 13-2011 · $81,680 | $106,184 | $9,600 | 91% |
| Digital Marketers | Market Research Analysts and Marketing Specialists SOC 13-1161 · $76,950 | $100,035 | $13,440 | 87% |
| Executive Assistants | Executive Secretaries and Executive Administrative Assistants SOC 43-6011 · $74,260 | $96,538 | $11,520 | 88% |
Figures are computed from the same dataset and the same 1.3× load the full Rate Index uses — an extract, not a separate calculation. Across all 45 roles with a BLS match the range is 79–94% and the median is 91%, so the rows above are representative rather than the flattering end.
Read this as a gross rate comparison. It sets our published starting rate against the loaded cost of the nearest US occupation, at 160 hours a month. It does not include what you still spend — onboarding, management time, tooling — which is why the savings we quote in ordinary copy are the more conservative 70–90%. Your actual rate depends on the brief.
