
The audit trail your auditor can read
Every decision recorded. Hosted by Zotniq or streamed to your SIEM.
Security posture
- On-device inspection by default. Prompt content never leaves the endpoint unless the customer's rule allows it.
- Encryption. TLS 1.3 in flight, AES-256 at rest.
- Regional residency. US and EU. Chosen per organization at onboarding. Data does not cross regions.
- Access control. SSO through your identity provider, role-based access within each organization, least-privilege access for Zotniq staff, break-glass access logged.
- Sub-processors. Listed below. 30-day notice before any change.
- Coordinated disclosure. See the Security page for scope, safe harbor, and how to report.
Data handling
Detection runs locally on the endpoint. Sensitive fields are masked on-device before any content leaves. By default, findings metadata (data type detected, which AI app, timestamp, enforcement decision) plus a redacted snippet of the finding is sent to Zotniq cloud. Customers who prefer that no text content leaves the endpoint can enable metadata-only mode.
Our detection model is proprietary and ships pre-trained on synthetic and public data. It does not learn from customer prompts. See the Privacy page for our full training posture.
Findings retention is customer-configurable per organization at onboarding based on your compliance framework. Backups rotate on a documented schedule. Full retention and deletion terms are in the DPA.
Compliance
| Framework | Status |
|---|---|
| SOC 2 Type II | In progress. Report expected 2027. Interim readiness documentation available under NDA. |
| GDPR / UK GDPR | DPA with Standard Contractual Clauses available. EU residency (eu-west-1) supported per organization. |
| HIPAA | Business Associate Agreement available. Prompt content stays on the endpoint by default. |
| HITRUST CSF | On the roadmap. Controls mapped to the HITRUST data protection domain today. Formal certification planned after SOC 2 Type II. |
| PCI DSS | We do not store, process, or transmit primary account numbers on our infrastructure. |
| GLBA (§501(b) Safeguards Rule) | Prevents non-public personal information (customer names, SSNs, account numbers) from leaving to AI tools without a rule allowance. Every enforcement decision recorded. |
| SR 11-7 (Federal Reserve model risk) | Not a model risk platform. We provide model documentation, validation notes, and change logs so bank customers can complete their SR 11-7 process. |
| ISO 27001 | On the roadmap. Controls modelled to ISO Annex A today. |
| EU AI Act (Article 12) | Every decision recorded with actor, rule, and framework mapping. Aligned with logging requirements. |
SOC 2 report, gap letter, DPA, and BAA available under NDA. Email info@zotniq.ai.
Incident response
If we detect a security event that affects customer data, we notify affected customer administrators without undue delay and, where required by law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
To report a suspected incident, email security@zotniq.ai with a description, timing, and any evidence. Include the affected organization if you know it.
Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Compute and storage for the Zotniq cloud (findings ingestion, dashboard, audit log) | US-east-1 (US customers) · EU-west-1 (EU customers) |
| Cloudflare | DNS, edge network, WAF, TLS termination for public-facing endpoints | Global (traffic served from the nearest edge) |
| Kinde | Identity provider (SSO, session management for the Zotniq dashboard) | US |
| PostgreSQL on Amazon RDS | Application database (org state, rules, audit log metadata) | Per-org: US-east-1 or EU-west-1 |
Contact
Security disclosures: security@zotniq.ai
Privacy and data-subject rights: privacy@zotniq.ai
Compliance, audit, and anything else: info@zotniq.ai