Security and privacy are design and operating responsibilities, not badges added at launch. OneZero identifies the people, information, systems, vendors, access, decisions, retention, and failure paths that shape an appropriate project plan.
Use only the data, access, and vendors the workflow actually needs.
The controls for a public marketing page differ from a client portal, internal assistant, health-administration workflow, payment connection, or multi-role custom application. Scope should match the sensitivity and consequence of the system.
What we will not pretend: This page describes an approach, not a certification, legal opinion, penetration-test result, regulatory guarantee, insurance statement, or promise that every possible control applies to every project.
Three boundaries to define early
What data enters, where it comes from, and why
Identify public, confidential, personal, financial, health, employee, client, and operational information before a tool or vendor is selected.
Who can see, change, approve, export, and delete
Use named roles, least necessary access, separate environments, appropriate authentication, logging, and an offboarding route.
Who monitors, updates, recovers, and responds
Plan software updates, vendor changes, backups, logs, errors, support, retention, incident contacts, and recovery before launch.
Questions included in responsible discovery
The project record should make the proposed data flow and operational owner inspectable.
- Purpose, minimum necessary fields, source, accuracy, consent, and lawful authority
- Classification, storage, processing, transfer, backup, retention, deletion, and export
- User roles, authentication, authorization, credentials, devices, vendors, and administrator access
- Development, test, staging, and production separation and representative test data
- Encryption and transport expectations supported by the selected architecture and vendors
- Logging, monitoring, dependency updates, vulnerability handling, incident contact, recovery, and communication
- Human review, prohibited uses, source boundaries, evaluation, and escalation for AI-assisted work
The client remains an essential control owner
OneZero can design and implement agreed controls, document assumptions, and support operations. The client controls business policy, authorized users, source accuracy, account access, staff behaviour, consent, legal basis, retention decisions, and sector obligations unless a written agreement assigns a specific responsibility otherwise.
Use specialists when the consequence demands it
Legal, privacy, compliance, accessibility, security, clinical, engineering, payment, insurance, and regulatory review may require appropriately qualified specialists. Their requirements can be incorporated into scope, testing, and acceptance.
Security and privacy through the project
- Discover the boundary. Inventory users, data, systems, vendors, devices, environments, decisions, threats, obligations, and prohibited uses.
- Define proportionate controls. Record responsibilities, access, architecture, retention, logging, testing, support, acceptance, and unresolved risks.
- Build and verify. Use controlled access, appropriate test data, review gates, dependency checks, acceptance cases, and specialist evidence where scope requires it.
- Operate and change responsibly. Maintain accounts, vendors, software, logs, backups, source knowledge, user access, incidents, and change records after launch.
Questions buyers usually ask
Is OneZero certified to a security standard?
No certification is claimed on this page. If a project requires a specific certification, audit, control framework, or vendor qualification, that requirement must be raised and verified during procurement and scope.
Can you guarantee a system is secure or compliant?
No responsible provider can promise zero risk or blanket compliance. OneZero can implement and document agreed controls, test defined requirements, disclose known limits, and work with qualified reviewers.
Will our information be used to train AI?
No such use is assumed. Any AI vendor, model, retention, training, processing, data-location, and opt-in terms must be explicitly reviewed for the proposed workflow before private information is connected.
Can you sign our security or data agreement?
Requirements can be reviewed during procurement. Acceptance depends on the actual services, vendors, responsibilities, insurance, legal terms, and ability to meet the stated controls.
Put the sensitive questions on the table before the demo.
Tell us who uses the proposed system, what information it touches, what a failure would mean, and which policies or specialist requirements already apply.