Purpose bound
Access is linked to defined work and removed when no longer required.
Zaivit trust centre
This page separates current website behaviour, engagement practices, and independent assurance. It avoids implying certifications or controls that have not been verified.
CURRENT WEBSITE STATE
The current site is static. It does not use analytics, advertising pixels, cookies, externally hosted fonts, account systems, or server-side enquiry forms. The product brief is generated entirely in the browser and leaves the device only when a visitor deliberately copies or downloads it.
DELIVERY SECURITY
For each engagement, the applicable delivery plan should identify owners, tools, evidence, exceptions, and review points for:
These are engagement practices, not claims that every control applies to every product or that Zaivit currently holds a security certification.
DATA HANDLING PRINCIPLES
Access is linked to defined work and removed when no longer required.
Client-managed repositories, environments, and identity are preferred where practical.
Copies, logs, artifacts, and deletion responsibilities are agreed before processing.
Relevant delivery records and operating knowledge are prepared for client ownership.
ASSURANCE BOUNDARIES
Zaivit can translate relevant requirements from frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and WCAG into technical controls and delivery evidence when they are within the agreed scope. Independent assessors issue certifications and audit opinions. Qualified legal counsel determines legal compliance.
PROCUREMENT CHECKLIST
Before an engagement begins, the parties should confirm legal identity, scope, ownership, confidentiality, access, data handling, subprocessors, retention, service expectations, incident contacts, insurance, and exit responsibilities. The applicable terms depend on the work and must be agreed in signed documents.
Download the evaluation checklistPRIVACY NOTICE
Zaivit does not receive the selections entered in the brief builder. No cookies or local storage are used, and no analytics request is sent.
The site is hosted on Cloudflare Pages. To serve and protect it, Cloudflare processes request metadata such as IP address, user agent, and requested URL under its own terms. Cloudflare operates a global network, so this processing may occur outside India. Zaivit runs no server of its own and receives no identifiable visitor logs.
Email is the only channel that reaches Zaivit. If you write to the address published on this site, Zaivit receives your address and whatever you choose to include, and uses it only to respond. It is kept only for as long as the enquiry and any resulting engagement require. To ask what is held, to request correction or deletion, or to raise a grievance, write to that same address.
ACCESSIBILITY
The site uses semantic landmarks, keyboard-operable controls, visible focus, labelled form fields, responsive layouts, and reduced-motion support. It has been checked at 375, 768, 1024, and 1440 pixel widths. This is not an independent WCAG conformance audit.
WEBSITE TERMS
Website descriptions, sample artifacts, engagement horizons, and framework references are informational. Commercial scope, responsibilities, fees, service levels, intellectual-property terms, warranties, and data-processing terms must be agreed in signed engagement documents. Sample artifacts may be reused for evaluation but must not be presented as customer evidence.