Security built in from day one.
No PII retention. No cross-contamination. Every task spun up clean, and torn down like it was never seen.
The left hand shouldn't know what the right hand is doing.
Decides what to do, and keeps a record.
Holds your policies, credentials, and context. Logs down its decisions.
Does the actual work.
Works in its own locked-down desktop, one task at a time. It can suggest, but never decide.
The short version, for your security folks.
| Topic | Summary |
|---|---|
| Hosting & residency | Amazon Web Services (AWS), region us-east-2 (Ohio). All data resides in the United States, inside Zomma’s virtual private cloud (VPC). |
| Encryption | Encrypted in transit (TLS 1.2+) and at rest (AES-256). |
| Model training | Your data is not used to train Zomma’s or any provider’s foundation models. |
| Credentials | Application logins are entered in a secure prompt, stored encrypted in a dedicated vault, never shown in chat, and never sent to an AI model. 1Password integration is currently supported. |
| Agent actions | Actions run through policy checks, with human authorization for sensitive steps and full audit logs. Read- and draft-only scope available. |
| Access control | Per-organization tenant isolation, SSO/SAML via WorkOS, role-based access, immutable audit trail. |
| Compliance | GDPR/CCPA-aligned data handling. SOC 2 Type II certification is pending. |
Our rigorous approach to agentic trust and security is our competitive advantage.
Straight answers to the common questions.
Is data access read-only, or can agents change things?
Zomma can both read and make changes, but it can’t change anything on its own. Every change is checked against your rules, anything that leaves your systems needs a person to approve it, and all of it is logged. If you prefer, we can set it up to read-only or draft-only, so it never makes a change at all.
Where is the data stored?
All data resides within Zomma’s private AWS environment in us-east-2 (US East / Ohio), with encrypted storage at rest and in transit. Sensitive credentials are kept in an isolated vault, and our cloud desktops are wiped clean after every session.
Bring your reviewer. We'll answer everything.
A 30-minute walkthrough of our controls, architecture, and audit trail, with your security lead in the room.
- Data Processing Agreement (DPA), if required
- Our full sub-processor list
- SOC 2 Type II certification timelines
- A technical walkthrough of how it works
- Answers to your security questionnaires