TRUST CENTER

Trust should be inspectable, not assumed

Review how ZoikoSuite approaches security, compliance, privacy, data residency, evidence, responsible AI, accessibility, policies, reliability and independent assurance — with every material claim designed to show its status, scope, review date and source.

Trust Center Isometric Architecture
CLAIM STATUS LEGEND AND TRUST METHODOLOGY

Nine statuses, because not every claim is equally certain

A trust center loses credibility when everything looks equally verified. Status is text-first; colour reinforces but never carries the meaning alone.

Claim Status Legend and Trust Methodology UI
Trust Diligence Finder

Eleven trust destinations

Trust Center is the hub. Depth lives in each destination rather than being duplicated inconsistently here. Destinations that are not yet published are shown without a link.

Security Overview

Control categories across identity, access, segregation of duties, encryption, logging and operational security.

READINESSIMPLEMENTED CONTROLS
DESTINATION NOT PUBLISHED

Compliance Overview

Framework alignment and readiness work, separated from any independent certification.

READINESS
DESTINATION NOT PUBLISHED

Certifications

Independent assurance where it exists, with issuer, scope, period and access rule.

NONE CURRENTLY HELD
DESTINATION NOT PUBLISHED

Data Residency

Region, storage, processing, backup, replication, key custody and support-access behaviour.

ARCHITECTURE TARGETBY DEPLOYMENT
DESTINATION NOT PUBLISHED

Privacy Architecture

Data classification, purpose, access scope, retention references and review states.

CURRENT ARCHITECTUREPHASED DELIVERY
DESTINATION NOT PUBLISHED

Evidence Architecture

How decisions, workflows, documents, events and manifests form audit evidence.

CURRENT ARCHITECTUREPHASED DELIVERY
DESTINATION NOT PUBLISHED

Responsible AI

AI governance boundaries, human decision requirements and evidence expectations.

CURRENT ARCHITECTURE
DESTINATION NOT PUBLISHED

Accessibility

Design standard, conformance status, documentation and the feedback path.

IN VALIDATION
DESTINATION NOT PUBLISHED

Policies

Policy library, legal notices, DPA, subprocessors and disclosure routes.

PUBLISHED ON REQUEST
DESTINATION NOT PUBLISHED

System Status

Live service health, incident transparency model and historical record.

LIVE STATUS SOURCE
DESTINATION NOT PUBLISHED

Platform architecture

Source ownership, authority model, integration contracts and deployment options — published today.

PUBLISHED
Security Overview Preview

Control categories, each with its status

Categories and posture without sensitive architectural detail. Nothing here reveals configuration that would assist an attacker.

Identity & access

CURRENT ARCHITECTURE

SSO, MFA, workload identity, role and attribute authorization.

Segregation of duties

CURRENT ARCHITECTURE

Preparer, reviewer, approver and executor independently permissioned.

Encryption

IMPLEMENTED

At rest and in transit, stated per deployment rather than universally.

Logging & audit telemetry

IMPLEMENTED

Governance and access events linked to actor, source, object and decision.

Data classification

IMPLEMENTED

Public, internal, confidential and restricted classes with policy-aware access.

Key management

BY DEPLOYMENT

Customer-managed key availability varies by deployment option and region.

Vulnerability management

IN VALIDATION

Scanning and remediation process; next evidence gate under review.

Supply chain security

PLANNED

Signed artifacts, provenance and SBOM as roadmap items. No badge displayed.

Penetration test report

CONTROLLED ACCESS

Released under NDA through security review, subject to scope and date.

COMPLIANCE AND CERTIFICATIONS

Framework alignment is not certification

These are kept strictly separate. Alignment describes how the control model maps to a framework; certification requires an independent issuer, scope and period.

SOC 2

Control mapping and readiness work underway. Next evidence gate is a readiness assessment.

READINESS

ISO/IEC 27001

Control mapping against the standard. No statement of applicability is published.

READINESS

NIST CSF 2.0

Referenced as a risk-management framework for design context only.

REFERENCE FRAMEWORK

Sector frameworks

PCI DSS, HIPAA, FedRAMP, NERC CIP and equivalents are addressed per industry with applicability states.

BY SCOPE AND SECTOR
Framework Alignment and Certification Illustration
PRIVACY, DATA RESIDENCY AND SOVEREIGNTY

Residency is a lifecycle question, not a single region

A primary storage region does not mean every lifecycle stage stays in that region. Each stage carries its own status.

Residency is a lifecycle question, not a single region illustration
EVIDENCE ARCHITECTURE

Six layers that form audit evidence

How decisions, workflows, documents, events and manifests combine into something an auditor can inspect.

01

Governance decision

Actor, entity, jurisdiction, policy basis, authorization outcome, timestamp.

DECISION CARD • REFERENCE ID
02

Workflow history

Every transition, approver, delegation, rejection, escalation and rationale.

CHRONOLOGICAL TIMELINE
03

Document lineage

Version, integrity hash, access history, signature status, retention reference.

DOCUMENT EVIDENCE DRAWER
04

Operational event

Typed event, source service, object, actor or principal, correlation.

EVENT DETAIL PANEL
05

Evidence manifest

Scenario-specific package with controlled export and its own access record.

PACKAGE INDEX • EXPORT CONTROL
06

Integrity controls

Append-only records and tamper-evident chains, with cryptographic validation where implemented.

INTEGRITY STATUS • VALIDATION
RESPONSIBLE AI

Boundaries that hold in every product surface

These apply platform-wide and are not relaxed by configuration, deployment option or customer agreement.

AI MAY

  • Detect anomalies against configured expectations
  • Forecast exposure from source data, labelled as a projection
  • Extract obligations, clauses and metadata with provenance
  • Prioritize exceptions for human review
  • Summarize a decision basis with its sources cited
  • Provide decision support to a named reviewer

AI MAY NOT

  • Make any autonomous material decision
  • Bypass authority, approval or segregation requirements
  • Alter source truth in any system of record
  • Satisfy an evidence requirement on its own
  • Act on a customer, patient, claimant or constituent
  • Substitute for professional or regulated judgment
ACCESSIBILITY, POLICIES AND RELIABILITY

Three areas, three honest positions

Each states what exists today, what does not, and how to obtain what is not published.

ACCESSIBILITY

Product designed to WCAG 2.2 AA. Conformance documentation such as an ACR or VPAT is in validation, and no conformity claim is made without tested evidence.

  • Keyboard operability and visible focus
  • Text-first status, never colour alone
  • 44×44 minimum touch targets
  • Feedback path published with the documentation

POLICIES AND LEGAL TRANSPARENCY

Policy library, legal notices and processing documentation. Each carries a version, effective date and owner.

  • Privacy Policy · Terms · Cookie notice
  • Data Processing Agreement on request
  • Subprocessor list with change notification
  • Vulnerability disclosure route

RELIABILITY AND SYSTEM STATUS

A live status source is the authoritative view of service health. This page does not restate it, because a cached status is worse than none.

  • Current component health
  • Incident history and post-incident reviews
  • Scheduled maintenance notices
  • No uptime percentage or availability guarantee is published here
PROOF AND VALIDATION LADDER

What can be public, what is controlled, what does not exist

Five rungs kept separate rather than blended. Two of them are currently empty, and that is stated rather than obscured.

Architecture proof

Published source ownership, authority model, evidence architecture and integration contracts. Inspectable today without a conversation.

PUBLIC

Product proof

Annotated interfaces with synthetic data and an inspectable end-to-end governed scenario.

PUBLIC

Validation status

Per-item claim states across capability, coverage, integration, security and residency.

PUBLIC PER ITEM

Controlled evidence

Security questionnaires, test reports and architecture briefs where they exist — released under NDA through security review.

CONTROLLED ACCESS

Independent assurance

Third-party certification, attestation or assessment for a stated scope and period.

NOT AVAILABLE

Customer proof

Approved customer stories with evidence class, period and limitations.

NONE APPROVED
SECURITY REVIEW AND PROCUREMENT HANDOFF

Route qualified diligence to the right evidence

Minimum context so the response addresses your actual scope rather than a generic pack. Controlled-access evidence is released under NDA.

WHAT A SECURITY REVIEW CAN OBTAIN

  • Completed security questionnaire · scoped to your deployment
  • Architecture brief · source ownership, data flows, integration contracts
  • Test evidence · where it exists, under NDA, with scope and date stated
  • Residency answer · per lifecycle stage for your deployment option
  • Policy pack · DPA, subprocessors, retention and disclosure routes
  • Gap statement · what is not available, said directly

Start a security review

Six fields. Enough to scope a response, nothing more.

We use your information to respond to this request. Consent is never pre-checked. See the Privacy Policy.

NEXT STEP

Diligence first, demo second

If your security or procurement team needs evidence, start a review — it routes to the actual documents rather than a sales conversation. If you have what you need and want to see the product govern a real decision, book a demo.

No certification, compliance status, uptime commitment, residency guarantee or capability availability is committed outside an approved commercial document.

Book enterprise demo

Every section of this page was readable without it.

We use your information to respond to this request. Consent is never pre-checked. See the Privacy Policy.

FREQUENTLY ASKED QUESTIONS

Certification, privacy, residency, AI and access

Direct first sentences, then qualified detail. Every answer is present in the page source.

No. No independent certification is currently held, and no certification logo appears anywhere on this site.

Control mapping and readiness work are underway for both, carrying the status "readiness" with a next evidence gate. A logo will appear only when an issuer, scope, period and access rule can be published alongside it. See the separation