Trust should be inspectable, not assumed
Review how ZoikoSuite approaches security, compliance, privacy, data residency, evidence, responsible AI, accessibility, policies, reliability and independent assurance — with every material claim designed to show its status, scope, review date and source.

Nine statuses, because not every claim is equally certain
A trust center loses credibility when everything looks equally verified. Status is text-first; colour reinforces but never carries the meaning alone.

Eleven trust destinations
Trust Center is the hub. Depth lives in each destination rather than being duplicated inconsistently here. Destinations that are not yet published are shown without a link.
Security Overview
Control categories across identity, access, segregation of duties, encryption, logging and operational security.
Compliance Overview
Framework alignment and readiness work, separated from any independent certification.
Certifications
Independent assurance where it exists, with issuer, scope, period and access rule.
Data Residency
Region, storage, processing, backup, replication, key custody and support-access behaviour.
Privacy Architecture
Data classification, purpose, access scope, retention references and review states.
Evidence Architecture
How decisions, workflows, documents, events and manifests form audit evidence.
Responsible AI
AI governance boundaries, human decision requirements and evidence expectations.
Accessibility
Design standard, conformance status, documentation and the feedback path.
Policies
Policy library, legal notices, DPA, subprocessors and disclosure routes.
System Status
Live service health, incident transparency model and historical record.
Platform architecture
Source ownership, authority model, integration contracts and deployment options — published today.
Control categories, each with its status
Categories and posture without sensitive architectural detail. Nothing here reveals configuration that would assist an attacker.
Identity & access
SSO, MFA, workload identity, role and attribute authorization.
Segregation of duties
Preparer, reviewer, approver and executor independently permissioned.
Encryption
At rest and in transit, stated per deployment rather than universally.
Logging & audit telemetry
Governance and access events linked to actor, source, object and decision.
Data classification
Public, internal, confidential and restricted classes with policy-aware access.
Key management
Customer-managed key availability varies by deployment option and region.
Vulnerability management
Scanning and remediation process; next evidence gate under review.
Supply chain security
Signed artifacts, provenance and SBOM as roadmap items. No badge displayed.
Penetration test report
Released under NDA through security review, subject to scope and date.
Framework alignment is not certification
These are kept strictly separate. Alignment describes how the control model maps to a framework; certification requires an independent issuer, scope and period.
SOC 2
Control mapping and readiness work underway. Next evidence gate is a readiness assessment.
ISO/IEC 27001
Control mapping against the standard. No statement of applicability is published.
NIST CSF 2.0
Referenced as a risk-management framework for design context only.
Sector frameworks
PCI DSS, HIPAA, FedRAMP, NERC CIP and equivalents are addressed per industry with applicability states.

Residency is a lifecycle question, not a single region
A primary storage region does not mean every lifecycle stage stays in that region. Each stage carries its own status.

Six layers that form audit evidence
How decisions, workflows, documents, events and manifests combine into something an auditor can inspect.
Governance decision
Actor, entity, jurisdiction, policy basis, authorization outcome, timestamp.
Workflow history
Every transition, approver, delegation, rejection, escalation and rationale.
Document lineage
Version, integrity hash, access history, signature status, retention reference.
Operational event
Typed event, source service, object, actor or principal, correlation.
Evidence manifest
Scenario-specific package with controlled export and its own access record.
Integrity controls
Append-only records and tamper-evident chains, with cryptographic validation where implemented.
Boundaries that hold in every product surface
These apply platform-wide and are not relaxed by configuration, deployment option or customer agreement.
AI MAY
- •Detect anomalies against configured expectations
- •Forecast exposure from source data, labelled as a projection
- •Extract obligations, clauses and metadata with provenance
- •Prioritize exceptions for human review
- •Summarize a decision basis with its sources cited
- •Provide decision support to a named reviewer
AI MAY NOT
- •Make any autonomous material decision
- •Bypass authority, approval or segregation requirements
- •Alter source truth in any system of record
- •Satisfy an evidence requirement on its own
- •Act on a customer, patient, claimant or constituent
- •Substitute for professional or regulated judgment
Three areas, three honest positions
Each states what exists today, what does not, and how to obtain what is not published.
ACCESSIBILITY
Product designed to WCAG 2.2 AA. Conformance documentation such as an ACR or VPAT is in validation, and no conformity claim is made without tested evidence.
- •Keyboard operability and visible focus
- •Text-first status, never colour alone
- •44×44 minimum touch targets
- •Feedback path published with the documentation
POLICIES AND LEGAL TRANSPARENCY
Policy library, legal notices and processing documentation. Each carries a version, effective date and owner.
- •Privacy Policy · Terms · Cookie notice
- •Data Processing Agreement on request
- •Subprocessor list with change notification
- •Vulnerability disclosure route
RELIABILITY AND SYSTEM STATUS
A live status source is the authoritative view of service health. This page does not restate it, because a cached status is worse than none.
- •Current component health
- •Incident history and post-incident reviews
- •Scheduled maintenance notices
- •No uptime percentage or availability guarantee is published here
What can be public, what is controlled, what does not exist
Five rungs kept separate rather than blended. Two of them are currently empty, and that is stated rather than obscured.
Architecture proof
Published source ownership, authority model, evidence architecture and integration contracts. Inspectable today without a conversation.
Product proof
Annotated interfaces with synthetic data and an inspectable end-to-end governed scenario.
Validation status
Per-item claim states across capability, coverage, integration, security and residency.
Controlled evidence
Security questionnaires, test reports and architecture briefs where they exist — released under NDA through security review.
Independent assurance
Third-party certification, attestation or assessment for a stated scope and period.
Customer proof
Approved customer stories with evidence class, period and limitations.
Route qualified diligence to the right evidence
Minimum context so the response addresses your actual scope rather than a generic pack. Controlled-access evidence is released under NDA.
WHAT A SECURITY REVIEW CAN OBTAIN
- Completed security questionnaire · scoped to your deployment
- Architecture brief · source ownership, data flows, integration contracts
- Test evidence · where it exists, under NDA, with scope and date stated
- Residency answer · per lifecycle stage for your deployment option
- Policy pack · DPA, subprocessors, retention and disclosure routes
- Gap statement · what is not available, said directly
Start a security review
Six fields. Enough to scope a response, nothing more.
Diligence first, demo second
If your security or procurement team needs evidence, start a review — it routes to the actual documents rather than a sales conversation. If you have what you need and want to see the product govern a real decision, book a demo.
No certification, compliance status, uptime commitment, residency guarantee or capability availability is committed outside an approved commercial document.
Book enterprise demo
Every section of this page was readable without it.
Certification, privacy, residency, AI and access
Direct first sentences, then qualified detail. Every answer is present in the page source.
No. No independent certification is currently held, and no certification logo appears anywhere on this site.
Control mapping and readiness work are underway for both, carrying the status "readiness" with a next evidence gate. A logo will appear only when an issuer, scope, period and access rule can be published alongside it. See the separation