The boundary your CISO actually wanted.

z0.ai is built to be reviewed. The controls below are what we'll walk through on a security call — and what your auditors will see in the log.

Controls matrix

What we'll send before the call.

A snapshot of the security posture, ordered the way most vendor reviews ask for it. The full PDF (with policies and our standard DPA) is available on request.

Data residencyCustomer cloud, customer region. Enterprise tier deploys inside your AWS, Azure, or GCP account.
Tenant isolationPer-workspace, per-team, per-channel scoping. Memory and tool grants are scoped, not shared.
Model accessAnthropic and OpenAI by default. BYO model keys supported. Zero Data Retention with our model providers.
PII handlingDLP filters run before any prompt leaves Slack. Configurable redaction rules per workspace.
EgressApproved-destinations enforcement. Agents reach only the APIs and systems your admin allowed.
IdentitySSO via Slack on Team and Scale. SAML SSO + SCIM on Enterprise.
Audit logEvery prompt, response, tool call, approval, denial, and retry. Exportable to SIEM, DLP, SOAR, GRC.
Access reviewsQuarterly export for reviewers. Workspace admin, approver, auditor, and billing admin roles.
AttestationsSOC 2 Type II in progress. HIPAA in progress. AARM aligned. Named contact for compliance review on Enterprise.
Data we storeSee "What z0.ai stores" below — explicit list, no hand-waving.

Data flow

What happens between Slack and the model.

The path a prompt takes is short, deliberate, and logged at every step. No hidden hops; nothing leaves your perimeter on Enterprise.

  1. 1Step

    Slack message

    User mentions @Zero in an approved channel. The message is captured by the z0.ai Slack app — no third-party Slack proxy.

  2. 2Step

    DLP + scope check

    Configurable filters strip PII or block the request. Channel scope decides which tools and data the agent may use.

  3. 3Step

    Model call

    Prompt is sent to the configured model provider with Zero Data Retention. Tool calls go to pre-approved endpoints only.

  4. 4Step

    Audit + reply

    Response, tool calls, citations, and approvals are written to the audit log. Reply lands back in the originating Slack thread.

Defense in depth

Four boundaries, not one big one.

Runs in your cloud (Enterprise)

Single-tenant deployment in your AWS, Azure, or GCP. Customer-managed keys, customer-defined egress allowlist, customer-controlled retention.

Approved destinations only

An agent can only reach the APIs, systems, and channels your admin enumerated. Unknown destinations are denied, not warned.

Human approval for risky actions

Sensitive tool calls require explicit approval from a designated reviewer. The agent prepares; a person commits.

Per-tenant isolation

Memory, integrations, audit records, and tool grants live inside the workspace they were created in. Access doesn't drift as you grow.

Audit trail

Every run is a trace you can pull up later.

Prompts, tool calls, approvals, denials, timing, and process-level attribution — all attached to the run that produced them. Pull up any run, six months later, and see what the agent actually did.

app.z0.ai/admin · runs · trace
z0.ai admin console showing a run trace with timeline waterfall, process attributes, and metadata

What this means in practice

The four scenarios your security team will ask about.

Prompt injection

The agent only sees the tools, destinations, and memory the channel was scoped to. A poisoned prompt can't reach what wasn't pre-approved.

Bad tool plans

Approval gates and DLP sit between a generated plan and any real change. Dangerous calls are denied or queued for review, not executed.

Investigations

Prompts, responses, tool calls, denials, retries, citations, and usage records are kept. You can answer 'what did the agent do?' months later.

Access changes

Move a Slack route, swap a tool account, revoke a destination — the change is local. Other agents and other workspaces are not loosened.

Honesty section

What z0.ai stores.

z0.ai is not a zero-access product. We store the metadata required to run the service and produce an audit trail. We do not train models on your data. We do not sell customer data. Full list, no marketing rounding:

  • Tenant + workspace records. Org structure, billing tier, admin roles.
  • Slack route configuration. Which channels are scoped to which agents.
  • Integration metadata. OAuth tokens (encrypted at rest), connection state.
  • Prompt + response. User message, model response, tool calls, citations.
  • Run records. Status, retries, denials, approvals, checkpoint snapshots.
  • Audit + billing. Per-action audit entries, credit usage, per-run cost.
  • Memory + artifacts. Workspace-scoped agent memory, generated artifacts.

On Enterprise (BYOC): the items above live entirely inside your cloud account. z0.ai receives only operational telemetry (uptime, errors), and even that can be turned off at your request.

Send your security team.

We'll walk through the controls matrix, the data flow, and the audit log — before we talk about pricing.

We send the controls matrix and standard DPA before the first call.