Security

Security built in from day one.

No PII retention. No cross-contamination. Every task spun up clean, and torn down like it was never seen.

How it works

The left hand shouldn't know what the right hand is doing.

01
You ask Zomma in plain language.
Talk to Zomma like a teammate. Zomma works out what you want, but doesn’t act yet.
02
An orchestrator decides how to respond and act.
Your policies, settings, and credentials live in a separate control layer. It has the final say on what the agent can and can't do.
03
The runtime does the work. Nothing else.
Runs in isolation. No access to your policies, settings or credentials. Only the instructions it's been cleared to carry out.
04
Anything risky waits for you.
Moving money? Sending a batch email to current clients? It stops and waits for your explicit approval before taking action.
“Email the Q2 statement to the client.”
waiting for your OK
The orchestrator

Plans the steps, and keeps a record.

Holds your policies, credentials, and context. Logs down its decisions.

The runtime

Does the actual work.

Works in its own locked-down desktop, one task at a time. It can suggest, but never decide.

Security & trust at a glance

The short version, for your security folks.

TopicSummary
Hosting & residencyAmazon Web Services (AWS), region us-east-2 (Ohio). All data resides in the United States, inside Zomma’s virtual private cloud (VPC).
EncryptionEncrypted in transit (TLS 1.2+) and at rest (AES-256).
Model trainingYour data is not used to train Zomma’s or any provider’s foundation models.
CredentialsApplication logins are entered in a secure prompt, stored encrypted in a dedicated vault, never shown in chat, and never sent to an AI model. 1Password integration is currently supported.
Agent actionsActions run through policy checks, with human authorization for sensitive steps and full audit logs. Read- and draft-only scope available.
Access controlPer-organization tenant isolation, SSO/SAML via WorkOS, role-based access, immutable audit trail.
ComplianceGDPR/CCPA-aligned data handling. SOC 2 Type 1 audit.
Where your data goes

Your organization is the boundary.

WhatWhere it lives
The agentWorks inside your workspace, in a cloud desktop that is wiped after every session. Nothing is shared across customers. Each customer runs single-tenant.
Screenshots and case filesStored per organization, in Zomma’s AWS environment in us-east-2, with a retention period you set.
CredentialsStay in the isolated vault. They are never shown in chat and never sent to a model. 1Password is supported.
Model callsGo to Anthropic and OpenAI under zero data retention and no training on your data, agreed in writing.
Before you signA written data-flow description is available before any agreement is signed. Ask for it on the walkthrough.
Third-party services

Every third party that touches data, by name.

ProviderPurpose
Amazon Web ServicesHosting, region us-east-2 (Ohio).
AnthropicModel provider. Zero data retention, no training on your data.
OpenAIModel provider. Zero data retention, no training on your data.
VercelWebsite hosting and cookieless analytics for zommalabs.com.
1PasswordCredential vault integration.
GoogleCalendar booking.
Apollo.ioWebsite visitor identification on zommalabs.com, loaded only behind the cookie banner.
Your IT department asked

Straight answers to the common questions.

Is data access read-only, or can it change things?

Zomma can both read and make changes, but it cannot change anything on its own. Every change is checked against your rules, anything that leaves your systems needs a person to approve it, and all of it is logged. If you prefer, we can set it up read-only or draft-only, so it never makes a change at all.

Where is the data stored?

All data resides within Zomma’s private AWS environment in us-east-2 (US East, Ohio), with encrypted storage at rest and in transit. Sensitive credentials are kept in an isolated vault, and the cloud desktops are wiped clean after every session.

Does the agent decide anything on its own?

No. It recommends clear, escalate, or request more information, with the evidence under the recommendation. A person makes the decision, and a person clears every two-factor prompt. Both are logged.

Which third parties see our data?

The third-party services that touch your data are listed on this page: AWS for hosting, Anthropic and OpenAI as model providers under zero data retention and no training, 1Password for the credential vault, and Vercel, Google and Apollo.io for the website only. A written data-flow description is available before anything is signed.

What can our security team review before we sign?

A data processing agreement if required, the list of third-party services, the SOC 2 Type 1 audit report when it is issued, a technical walkthrough of how it works, and answers to your security questionnaires.

For your security team

Bring your reviewer. We'll answer everything.

A 30-minute walkthrough of our controls, architecture, and audit trail, with your security lead in the room.

  • Data Processing Agreement (DPA), if required
  • The third-party services listed on this page
  • SOC 2 Type 1 audit report, shared when it is issued
  • A technical walkthrough of how it works
  • Answers to your security questionnaires

Raise what your team can do.