Digital Zalmi

Company · Trust Center

Made to pass
your review.

Security reviews and procurement checks shouldn't require a meeting to start. This page answers the standard questions in advance — and where we haven't earned a certification yet, it says so, with the date we intend to.

01 — Who you're dealing with

Identity, verifiable.

Legal entity
Digital Zalmi (SMC-PVT) Limited
Registration
SECP, Pakistan
Headquarters
Charsadda, Khyber Pakhtunkhwa
Contact
hello@digitalzalmi.com · +92 331 651 1666
Physical visits
Welcome, by appointment

02 — Security posture

How your systems are protected.

Infrastructure we operate

Products run on DZPS — our own platform — on servers we administer directly: TLS everywhere, patched OS baselines, isolated tenants, monitored around the clock by our own tooling.

Access control

Role-based access on every product; administrative access is named, logged, and reviewed. No shared root credentials, no exceptions.

Backups & recovery

Automated encrypted backups with tested restores. Your data survives our hardware's bad day.

Audit trails

The DZPS audit service records privileged actions across products — when the question is 'who did what, when', the answer is a query.

03 — Data promises

Written here so you can hold us to them.

Your data is yours

Exportable on request, deleted on termination per the retention schedule in your agreement. We build the exit door before you need it.

No training on client data

AI features never train on your business data. Assessment and tool inputs are used only to produce your output — and anonymized aggregates only where we've said so in plain language on the page.

No selling, no sharing

We do not sell or share client or student data with third parties, full stop. Subprocessors (hosting, AI model APIs) are listed in agreements.

AI outputs labeled

Where AI generates advisory content (scores, estimates, drafts), it is labeled indicative — contractual commitments come from humans, in writing.

04 — Certifications, honestly

What's earned, what's next, what's not yet.

Now

TLS everywhere · role-based access · encrypted backups · audit logging · this public Trust Center

live
Next

Public status page with uptime history · published SLA tiers on every product

in build
Year 2

ISO 27001 certification program — the formal audit of everything above

planned
As earned

SOC 2 — when international product revenue justifies the audit

planned

We list planned certifications with timelines instead of implying them with badge-shaped graphics. If a claim on this page ever ages out, tell us — being corrected is part of the promise.

05 — Accessibility

WCAG 2.2 AA is the build standard.

This site is built to WCAG 2.2 AA: keyboard-complete navigation, visible focus, reduced-motion support, semantic structure, RTL/Urdu parity, and performance budgets that respect 3G connections. Found a barrier? Report it and we'll fix it — the conformance statement is a commitment, not a decoration.

Report an accessibility issue