
The audit trail your auditor can read
Every decision recorded. Hosted by Zotniq or streamed to your SIEM.
Security posture
- On-device inspection by default. Prompt content never leaves the endpoint unless the customer's rule allows it.
- Encryption. TLS 1.3 in flight, AES-256 at rest.
- Regional residency. US and EU. Chosen per organization at onboarding. Data does not cross regions.
- Access control. SSO through your identity provider, role-based access within each organization, least-privilege access for Zotniq staff, break-glass access logged.
- Sub-processors. Listed below. 30-day notice before any change.
- Coordinated disclosure. See the Security page for scope, safe harbor, and how to report.
Data handling
In monitor-only mode, prompt content stays on the device. Only findings metadata leaves. In enforcement mode the same rule applies: content leaves only if the customer's rule explicitly allows it.
Our detection model is proprietary and ships pre-trained on synthetic and public data. It does not learn from customer prompts. See the Privacy page for our full training posture.
Findings retention defaults to 90 days and is customer-configurable up to 7 years for audit purposes. Backups rotate out within 35 days of primary deletion.
Compliance
| Framework | Status |
|---|---|
| SOC 2 Type II | In progress. Report expected 2027. Interim readiness documentation available under NDA. |
| GDPR / UK GDPR | DPA with Standard Contractual Clauses available. EU residency (eu-west-1) supported per organization. |
| HIPAA | Business Associate Agreement available. Prompt content stays on the endpoint by default. |
| HITRUST CSF | On the roadmap. Controls mapped to the HITRUST data protection domain today. Formal certification planned after SOC 2 Type II. |
| PCI DSS | We do not store, process, or transmit primary account numbers on our infrastructure. |
| GLBA (§501(b) Safeguards Rule) | Prevents non-public personal information (customer names, SSNs, account numbers) from leaving to AI tools without a rule allowance. Every enforcement decision recorded. |
| SR 11-7 (Federal Reserve model risk) | Not a model risk platform. We provide model documentation, validation notes, and change logs so bank customers can complete their SR 11-7 process. |
| ISO 27001 | On the roadmap. Controls modelled to ISO Annex A today. |
| EU AI Act (Article 12) | Every decision recorded with actor, rule, and framework mapping. Aligned with logging requirements. |
SOC 2 report, gap letter, DPA, and BAA available under NDA. Email [email protected].
Incident response
If we detect a security event that affects customer data, we notify affected customer administrators without undue delay and, where required by law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
To report a suspected incident, email [email protected] with a description, timing, and any evidence. Include the affected organization if you know it.
Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| AWS | Compute, storage | US-east-1 · EU-west-1 |
| Cloudflare | DNS, edge, WAF | Global |
| Kinde | Identity | US |
| PostgreSQL (RDS) | Application database | Per-org region |
Contact
Security disclosures: [email protected]
Privacy and data-subject rights: [email protected]
Compliance, audit, and anything else: [email protected]