The boundary your CISO actually wanted.
z0.ai is built to be reviewed. The controls below are what we'll walk through on a security call — and what your auditors will see in the log.
Controls matrix
What we'll send before the call.
A snapshot of the security posture, ordered the way most vendor reviews ask for it. The full PDF (with policies and our standard DPA) is available on request.
| Data residency | Customer cloud, customer region. Enterprise tier deploys inside your AWS, Azure, or GCP account. |
| Tenant isolation | Per-workspace, per-team, per-channel scoping. Memory and tool grants are scoped, not shared. |
| Model access | Anthropic and OpenAI by default. BYO model keys supported. Zero Data Retention with our model providers. |
| PII handling | DLP filters run before any prompt leaves Slack. Configurable redaction rules per workspace. |
| Egress | Approved-destinations enforcement. Agents reach only the APIs and systems your admin allowed. |
| Identity | SSO via Slack on Team and Scale. SAML SSO + SCIM on Enterprise. |
| Audit log | Every prompt, response, tool call, approval, denial, and retry. Exportable to SIEM, DLP, SOAR, GRC. |
| Access reviews | Quarterly export for reviewers. Workspace admin, approver, auditor, and billing admin roles. |
| Attestations | SOC 2 Type II in progress. HIPAA in progress. AARM aligned. Named contact for compliance review on Enterprise. |
| Data we store | See "What z0.ai stores" below — explicit list, no hand-waving. |
Data flow
What happens between Slack and the model.
The path a prompt takes is short, deliberate, and logged at every step. No hidden hops; nothing leaves your perimeter on Enterprise.
- 1Step
Slack message
User mentions @Zero in an approved channel. The message is captured by the z0.ai Slack app — no third-party Slack proxy.
- 2Step
DLP + scope check
Configurable filters strip PII or block the request. Channel scope decides which tools and data the agent may use.
- 3Step
Model call
Prompt is sent to the configured model provider with Zero Data Retention. Tool calls go to pre-approved endpoints only.
- 4Step
Audit + reply
Response, tool calls, citations, and approvals are written to the audit log. Reply lands back in the originating Slack thread.
Defense in depth
Four boundaries, not one big one.
Runs in your cloud (Enterprise)
Single-tenant deployment in your AWS, Azure, or GCP. Customer-managed keys, customer-defined egress allowlist, customer-controlled retention.
Approved destinations only
An agent can only reach the APIs, systems, and channels your admin enumerated. Unknown destinations are denied, not warned.
Human approval for risky actions
Sensitive tool calls require explicit approval from a designated reviewer. The agent prepares; a person commits.
Per-tenant isolation
Memory, integrations, audit records, and tool grants live inside the workspace they were created in. Access doesn't drift as you grow.
Audit trail
Every run is a trace you can pull up later.
Prompts, tool calls, approvals, denials, timing, and process-level attribution — all attached to the run that produced them. Pull up any run, six months later, and see what the agent actually did.

What this means in practice
The four scenarios your security team will ask about.
Prompt injection
The agent only sees the tools, destinations, and memory the channel was scoped to. A poisoned prompt can't reach what wasn't pre-approved.
Bad tool plans
Approval gates and DLP sit between a generated plan and any real change. Dangerous calls are denied or queued for review, not executed.
Investigations
Prompts, responses, tool calls, denials, retries, citations, and usage records are kept. You can answer 'what did the agent do?' months later.
Access changes
Move a Slack route, swap a tool account, revoke a destination — the change is local. Other agents and other workspaces are not loosened.
Honesty section
What z0.ai stores.
z0.ai is not a zero-access product. We store the metadata required to run the service and produce an audit trail. We do not train models on your data. We do not sell customer data. Full list, no marketing rounding:
- Tenant + workspace records. Org structure, billing tier, admin roles.
- Slack route configuration. Which channels are scoped to which agents.
- Integration metadata. OAuth tokens (encrypted at rest), connection state.
- Prompt + response. User message, model response, tool calls, citations.
- Run records. Status, retries, denials, approvals, checkpoint snapshots.
- Audit + billing. Per-action audit entries, credit usage, per-run cost.
- Memory + artifacts. Workspace-scoped agent memory, generated artifacts.
On Enterprise (BYOC): the items above live entirely inside your cloud account. z0.ai receives only operational telemetry (uptime, errors), and even that can be turned off at your request.
Send your security team.
We'll walk through the controls matrix, the data flow, and the audit log — before we talk about pricing.
We send the controls matrix and standard DPA before the first call.