Frequently asked questions
Compliance and security validation in one platform. Here are the questions we get asked most.
Compliance
What is Zerod exactly?
A compliance and security platform that covers the full cycle: implementing controls, generating the documentation an auditor asks for, collecting evidence, managing risks, assets, vendors and incidents, running internal audits, and publishing your security posture in a Trust Center. All in a single tool, in Spanish and English.
Which regulatory frameworks does it cover?
ISO 27001 and ISO 27002, ENS (RD 311/2022, Básica, Media and Alta categories), SOC 2, GDPR, NIS2, DORA, HIPAA, ISO 27701, ISO 42001 and the EU AI Act (Reg. EU 2024/1689). You can activate several at once and work them in parallel from the same dashboard.
How long does it take to be ready to certify?
Preparation goes from months to weeks. The work that normally takes six months of consulting (security policy, ISMS scope, risk assessment, Statement of Applicability, asset inventory, evidence collection, internal audit) is generated and maintained inside the platform. The certification date is still set by your certification body, which is who audits and issues the certificate: Zerod gets you ready for that audit, it does not replace it.
How is it different from international compliance platforms?
In three ways. First, real Spanish coverage: ENS with categorization and dimensions, a whistleblowing channel compliant with Law 2/2023, and an operational GDPR module, not a translated checklist. Second, the multi-client model built for MSPs and consultancies. Third, that continuous security validation is added on top of compliance, so your Trust Center does not just declare controls, it also shows what has been verified.
Can it manage multiple clients?
Yes. It is designed as a multi-tenant platform: an MSP or a consultancy manages several client organizations from a single account, with a hierarchy of sub-organizations, roles and permissions per organization, and independent plans per client.
Do I have to stop my engineering team?
No. You connect your cloud tools (AWS, Azure, Google Cloud), identity and email (Microsoft 365), code (GitHub, GitLab) and ticketing (Jira) once, and the platform collects findings and evidence continuously, associating them with the controls they correspond to. There is also integration with asset-management tools (NinjaOne, Atera, GLPI) to populate the inventory without manual work. Your engineers keep shipping product.
The documentation is generated by an AI. Will an auditor accept it?
The AI produces the draft, not the final document. Each type of document has its own structure and starts from a questionnaire about your organization that you must complete before generating anything, so the result speaks about your company and not a generic one. The draft is editable and goes through a review and approval flow: only once it is approved does it count as a valid document, it is recorded as a version, and it stops being marked as DRAFT in downloads. When you create an audit, the approved version of the documents that apply to it is frozen, so that whoever reviews that audit later sees what existed then and not the current version. The documents describe behaviors, responsibilities and expected evidence of your organization; they never reproduce the text of the standards.
Which AI model do you use and what happens to my data?
The platform supports Anthropic Claude, OpenAI and Google Gemini, selectable per organization. Keys are stored encrypted and consumption is controlled through credits with an auditable usage log. The AI is used to draft and suggest; the regulatory decisions and the approval of each document are always your team’s.
Does it only cover the documentation side?
No. Beyond controls and documents: risk management with a configurable methodology and matrix, asset inventory, vendor and subprocessor management, incidents, internal audits with findings and corrective actions, employee training and policy signing, and the whistleblowing channel.
Does it cover ENS with the level of detail the CCN requires?
Yes. The 73 measures of Annex II of RD 311/2022, with organizational category (Básica, Media or Alta), security dimensions, applicability calculated by category, and reinforcements. It includes generating the system Categorization document and a Statement of Applicability that respects applicability by category, not a flat list of controls.
What does the GDPR module include?
A record of processing activities, data-subject rights management, breach logging and notification, impact assessments, consent management, a subprocessor register, and a public privacy portal per organization where your customers exercise their rights and look up your data-protection contact information.
Does it include a whistleblowing channel?
Yes, compliant with Law 2/2023 and Directive EU 2019/1937: a public reporting channel per organization, anonymous case tracking, internal case management, and traceability. Available depending on plan.
Where is my data hosted?
In the European Union. All your organization’s information, including documents, evidence and records, is stored and processed on infrastructure located in the EU. The subprocessor list is not published openly; it is provided under a confidentiality agreement on request.
What is the Trust Center and what is published in it?
A public page at your organization’s URL where you show your active frameworks, your security documentation (open or under signed NDA), your subprocessors, and your security posture. It is what you send when a customer sends you a forty-question security questionnaire.
What is the difference between what I declare and what Zerod verifies?
In the Trust Center each item shows its provenance: what your team declares appears as self-reported, and what Zerod has checked through real tests appears as verified. The page also never publishes what you do not have: if a measure is not implemented, it simply does not appear, it is not presented as a gap and it is not dressed up. That distinction is what turns a trust page into proof.
Is Zerod certified?
Yes. Zerod is certified to ISO/IEC 27001:2022 and keeps the certification current through periodic audits by an accredited body. We apply the same discipline internally that we ask of our customers, and the current certificate is published in our Trust Center.
Pentesting
What asset types can you test?
The platform supports web application, API, mobile application, infrastructure, cloud, wireless network, IoT devices, smart contracts and red team exercises. Each asset type has its own scoping form and its own checklist template, so the scope is defined when the request is created and not afterwards. If an asset does not fit any of those categories, it is assessed case by case before quoting.
What is the difference between the engagement models?
Agile is the direct mode: the client requests a pentest, Zerod manages the proposals from qualified hackers, the client accepts one, and the assigned hacker works in direct contact with them. Enterprise groups several pentests under a single project, can assign more than one hacker to the same asset, and adds a project manager who acts as an intermediary and reviews the findings before sending them to the client. For certain scopes there is also PentAI, which adds AI to the testing with the same human validation of the findings; if it fits your case, we propose it when preparing the quote.
Do pentesting findings enter the compliance platform?
Yes, and not as a read-only view. An open high or critical severity finding becomes a real risk inside your risk register, with its full lifecycle. When it is resolved, that risk is closed and the finding becomes evidence linked to the technical-vulnerability-management controls of your active frameworks: A.8.8 in ISO 27001, CC7.1 in SOC 2, op.exp.4 in ENS, or Article 32 of the GDPR, according to the ones you have active.
A pentest with no findings also generates evidence. A clean result is proof that the control works, not the absence of information.
Non-conformities and corrective actions still live in the audits module, which is where they belong.
Is the pentesting done by AI or by people?
People. The core of Zerod Pentesting is a network of over 150 verified ethical hackers from different regions, and they are the ones who run the tests, validate what they find, and sign the report. We also offer PentAI, an option that brings AI into the testing process, always with human validation of the results before they reach the client. We do not deliver reports generated by AI alone.
How do you select the hackers in the network?
Sign-up is not open. Each candidate goes through an onboarding process where they declare their area of specialty, certifications, registered CVEs, zero day vulnerabilities, participation in recognition programs, talks, publications and their own tools, and a Zerod administrator manually approves or rejects the request before the account exists. Each hacker operates under a unique identifier within the platform, and in projects without direct communication their identity is not exposed to the client. Confidentiality and liability obligations are formalized in the agreement with each researcher.
What methodology do you follow?
Each asset type has a checklist template structured by categories, and the hacker records the result of each check with an explicit status: passed, failed, not applicable, or not covered due to a time limit. That means the client sees not only what was found but also what was tested and what was left out, which is usually the hard question in front of an auditor. The scope, the allowed time windows and the test restrictions are set before the start and are recorded in the project.
Who decides a finding is real and not a false positive?
Always a person. A finding only reaches the client when the researcher marks it as ready, with no exception based on where the result came from. In Enterprise there is a second layer: the project manager sees the team’s findings and decides which are sent to the client, with the ability to return one to the researcher stating the reason.
How is the severity of a finding scored?
Each finding carries its CVSS vector and the derived score, plus a description, the evidence, the remediation recommendation and the associated references. That score is what is exposed both in the platform and in the API, so that the client’s prioritization and ours use the same number. The vector is explicit and auditable, not a qualitative label assigned at discretion.
What do I receive when the pentest ends?
A report with the researcher’s conclusion, the detail of the findings included, the inventory of systems and services actually tested, and the supporting attachments. The report is sent formally and the client can accept it or return it with comments if something does not add up, so delivery is a reviewable act and not a PDF that appears in a folder. The project documentation remains permanently downloadable, also after the pentest is closed.
Do you verify that the vulnerabilities are fixed?
Yes, the retest is inside the pentest’s own cycle. Each finding has a status that reflects whether it is open, in retest, or resolved, and the project has a retest window after the testing phase during which the researcher checks the fixes. The client sees the status change in the platform, without needing to open a new project to verify a fix.
Does the report work as evidence for an auditor?
The report documents the scope, the methodology applied, the checks performed, the findings with their severity, and the retest result, which is the content an auditor usually asks for a technical security testing control. What a specific auditor accepts is decided by that auditor and their reference framework, not Zerod, so we do not promise acceptance. Zerod is certified to ISO/IEC 27001:2022, which applies to our own security management and not to the client’s.
How is it contracted and how is it billed?
Pentests are contracted per project, not per subscription: the client defines the scope, Zerod collects proposals from qualified hackers and presents the quote, and nothing starts until that quote is accepted. In Agile the start happens after payment, by card or with credits purchased in advance; in Enterprise the project starts with the approval of the overall quote and is billed as agreed. Credits let you buy capacity in advance and consume it across different projects over time. Automated code and application analysis does support a recurring subscription, with one analysis provisioned per billing cycle.
Can I take the findings into my own tools?
Yes. Findings can be exported to Jira and Linear, and when a finding’s status changes in Zerod that change propagates to the linked issue. There is also an API with its own key to query organizations, pentests and findings with their status and severity, and to create or edit pentest requests from your own systems. For day-to-day tracking, a Slack channel associated with the pentest can be enabled.
Get compliant. Prove your security.
Whether you're closing your next enterprise deal, raising your next round, or facing your next audit, Zerod gives you the security posture to prove it.
Or try Zerod first, no card required.