The audit trail your auditor can read

Every decision recorded. Hosted by Zotniq or streamed to your SIEM.

Security posture

  • On-device inspection by default. Prompt content never leaves the endpoint unless the customer's rule allows it.
  • Encryption. TLS 1.3 in flight, AES-256 at rest.
  • Regional residency. US and EU. Chosen per organization at onboarding. Data does not cross regions.
  • Access control. SSO through your identity provider, role-based access within each organization, least-privilege access for Zotniq staff, break-glass access logged.
  • Sub-processors. Listed below. 30-day notice before any change.
  • Coordinated disclosure. See the Security page for scope, safe harbor, and how to report.

Data handling

Detection runs locally on the endpoint. Sensitive fields are masked on-device before any content leaves. By default, findings metadata (data type detected, which AI app, timestamp, enforcement decision) plus a redacted snippet of the finding is sent to Zotniq cloud. Customers who prefer that no text content leaves the endpoint can enable metadata-only mode.

Our detection model is proprietary and ships pre-trained on synthetic and public data. It does not learn from customer prompts. See the Privacy page for our full training posture.

Findings retention is customer-configurable per organization at onboarding based on your compliance framework. Backups rotate on a documented schedule. Full retention and deletion terms are in the DPA.

Compliance

FrameworkStatus
SOC 2 Type IIIn progress. Report expected 2027. Interim readiness documentation available under NDA.
GDPR / UK GDPRDPA with Standard Contractual Clauses available. EU residency (eu-west-1) supported per organization.
HIPAABusiness Associate Agreement available. Prompt content stays on the endpoint by default.
HITRUST CSFOn the roadmap. Controls mapped to the HITRUST data protection domain today. Formal certification planned after SOC 2 Type II.
PCI DSSWe do not store, process, or transmit primary account numbers on our infrastructure.
GLBA (§501(b) Safeguards Rule)Prevents non-public personal information (customer names, SSNs, account numbers) from leaving to AI tools without a rule allowance. Every enforcement decision recorded.
SR 11-7 (Federal Reserve model risk)Not a model risk platform. We provide model documentation, validation notes, and change logs so bank customers can complete their SR 11-7 process.
ISO 27001On the roadmap. Controls modelled to ISO Annex A today.
EU AI Act (Article 12)Every decision recorded with actor, rule, and framework mapping. Aligned with logging requirements.

SOC 2 report, gap letter, DPA, and BAA available under NDA. Email [email protected].

Incident response

If we detect a security event that affects customer data, we notify affected customer administrators without undue delay and, where required by law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

To report a suspected incident, email [email protected] with a description, timing, and any evidence. Include the affected organization if you know it.

Sub-processors

ProviderPurposeRegion
Amazon Web Services (AWS)Compute and storage for the Zotniq cloud (findings ingestion, dashboard, audit log)US-east-1 (US customers) · EU-west-1 (EU customers)
CloudflareDNS, edge network, WAF, TLS termination for public-facing endpointsGlobal (traffic served from the nearest edge)
KindeIdentity provider (SSO, session management for the Zotniq dashboard)US
PostgreSQL on Amazon RDSApplication database (org state, rules, audit log metadata)Per-org: US-east-1 or EU-west-1

Contact

Security disclosures: [email protected]

Privacy and data-subject rights: [email protected]

Compliance, audit, and anything else: [email protected]