Security built in from day one.
No PII retention. No cross-contamination. Every task spun up clean, and torn down like it was never seen.
The left hand shouldn't know what the right hand is doing.
Plans the steps, and keeps a record.
Holds your policies, credentials, and context. Logs down its decisions.
Does the actual work.
Works in its own locked-down desktop, one task at a time. It can suggest, but never decide.
The short version, for your security folks.
| Topic | Summary |
|---|---|
| Hosting & residency | Amazon Web Services (AWS), region us-east-2 (Ohio). All data resides in the United States, inside Zomma’s virtual private cloud (VPC). |
| Encryption | Encrypted in transit (TLS 1.2+) and at rest (AES-256). |
| Model training | Your data is not used to train Zomma’s or any provider’s foundation models. |
| Credentials | Application logins are entered in a secure prompt, stored encrypted in a dedicated vault, never shown in chat, and never sent to an AI model. 1Password integration is currently supported. |
| Agent actions | Actions run through policy checks, with human authorization for sensitive steps and full audit logs. Read- and draft-only scope available. |
| Access control | Per-organization tenant isolation, SSO/SAML via WorkOS, role-based access, immutable audit trail. |
| Compliance | GDPR/CCPA-aligned data handling. SOC 2 Type 1 audit. |
Your organization is the boundary.
| What | Where it lives |
|---|---|
| The agent | Works inside your workspace, in a cloud desktop that is wiped after every session. Nothing is shared across customers. Each customer runs single-tenant. |
| Screenshots and case files | Stored per organization, in Zomma’s AWS environment in us-east-2, with a retention period you set. |
| Credentials | Stay in the isolated vault. They are never shown in chat and never sent to a model. 1Password is supported. |
| Model calls | Go to Anthropic and OpenAI under zero data retention and no training on your data, agreed in writing. |
| Before you sign | A written data-flow description is available before any agreement is signed. Ask for it on the walkthrough. |
Every third party that touches data, by name.
| Provider | Purpose |
|---|---|
| Amazon Web Services | Hosting, region us-east-2 (Ohio). |
| Anthropic | Model provider. Zero data retention, no training on your data. |
| OpenAI | Model provider. Zero data retention, no training on your data. |
| Vercel | Website hosting and cookieless analytics for zommalabs.com. |
| 1Password | Credential vault integration. |
| Calendar booking. | |
| Apollo.io | Website visitor identification on zommalabs.com, loaded only behind the cookie banner. |
Our rigorous approach to agentic trust and security is our competitive advantage.
Straight answers to the common questions.
Is data access read-only, or can it change things?
Zomma can both read and make changes, but it cannot change anything on its own. Every change is checked against your rules, anything that leaves your systems needs a person to approve it, and all of it is logged. If you prefer, we can set it up read-only or draft-only, so it never makes a change at all.
Where is the data stored?
All data resides within Zomma’s private AWS environment in us-east-2 (US East, Ohio), with encrypted storage at rest and in transit. Sensitive credentials are kept in an isolated vault, and the cloud desktops are wiped clean after every session.
Does the agent decide anything on its own?
No. It recommends clear, escalate, or request more information, with the evidence under the recommendation. A person makes the decision, and a person clears every two-factor prompt. Both are logged.
Which third parties see our data?
The third-party services that touch your data are listed on this page: AWS for hosting, Anthropic and OpenAI as model providers under zero data retention and no training, 1Password for the credential vault, and Vercel, Google and Apollo.io for the website only. A written data-flow description is available before anything is signed.
What can our security team review before we sign?
A data processing agreement if required, the list of third-party services, the SOC 2 Type 1 audit report when it is issued, a technical walkthrough of how it works, and answers to your security questionnaires.
Bring your reviewer. We'll answer everything.
A 30-minute walkthrough of our controls, architecture, and audit trail, with your security lead in the room.
- Data Processing Agreement (DPA), if required
- The third-party services listed on this page
- SOC 2 Type 1 audit report, shared when it is issued
- A technical walkthrough of how it works
- Answers to your security questionnaires