Why we publish our security gaps

By Team ZekoHR · 18 September 2026 · 2 min read

Two developers working through a problem at one screen

Go to our security and trust page and scroll to the bottom. You will find a section most vendors would never ship: "What we do not yet have, stated plainly." No SOC 2 yet. No external penetration test yet. A restore rehearsal that is still on the checklist.

Publishing that list made us nervous. Here is why we did it anyway.

Security pages are usually marketing pages

Read ten HR software trust pages and you will see the same shields, the same padlock icons, the same sentence about "bank-grade encryption". What you will almost never see is a date, a scope, or a gap.

That is because most trust pages are written by marketing teams to end a conversation. Ours is written by the people who operate the system, to start one. We think the difference matters when the data in question is salaries, PAN numbers and grievance reports.

What candour actually costs

Being specific about gaps has a price. A checklist-driven procurement team can read our page, see "no SOC 2", and disqualify us in thirty seconds. That has a real cost for a young product.

But consider what the alternative buys. If we hid the gaps behind vague language, we would win exactly the customers who will feel misled later. Trust that is borrowed has to be paid back with interest.

What candour buys you

A gap stated in public is a gap we cannot quietly deprioritise. Our page says an external penetration test is committed before public launch. That sentence is now a commitment with an audience.

It also changes the conversation with security-minded buyers. Instead of asking us to decode marketing language, they can read exactly what is live: mandatory 2FA for our staff, tenant isolation enforced twice and tested in CI on every change, time-boxed support access written to your own audit log with both identities. Then they can weigh the gaps themselves, with real information.

The test we apply

Before anything goes on the trust page, it has to pass one test: could our own engineers read this sentence and wince? If a claim is worded to sound bigger than the system it describes, it fails. If a gap is missing, the page fails.

We would rather lose a deal on the truth than win one on a shield icon.

This post describes our approach as of September 2026. The trust page itself is always the current version, and it changes as controls go live.

← All posts