> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zerodrift.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Certifications, deployment, data handling, and how to request reports.

## Certifications and compliance

ZeroDrift is SOC 2 Type II and ISO 27001 certified, and supports customers'
GDPR and HIPAA compliance requirements.

## Deployment

ZeroDrift supports multi-tenant cloud and private-cloud deployments. Customer-
managed VPC and on-premises deployments are not generally available. Contact
[support@zerodrift.ai](mailto:support@zerodrift.ai) to discuss deployment and
data-residency requirements.

## Data handling

* Content and verdict retention windows are documented in
  [Data Retention](/data-retention).
* Customer data is not used to train ZeroDrift or third-party AI models.
* Connected Notion, Linear, Confluence, and Google Drive sources are read-only.

## Access

* API keys are shown once when created.
* Keys can have read-only or full-access permissions.
* Rulepacks can be scoped per key.

## Reports and subprocessors

Review ZeroDrift's security posture, request SOC 2 and ISO 27001 reports, and
see the current subprocessor list in the
[ZeroDrift Trust Center](https://app.vanta.com/zerodrift.ai/trust/8dwp517ay48r0q3abhwy09).
