Security

Security built in from day one.

No PII retention. No cross-contamination. Every task spun up clean, and torn down like it was never seen.

How it works

The left hand shouldn't know what the right hand is doing.

01
You ask Zomma in plain language.
Talk to Zomma like a teammate. Zomma works out what you want, but doesn’t act yet.
02
An orchestrator decides how to respond and act.
Your policies, settings, and credentials live in a separate control layer. It has the final say on what the agent can and can't do.
03
The runtime does the work. Nothing else.
Runs in isolation. No access to your policies, settings or credentials. Only the instructions it's been cleared to carry out.
04
Anything risky waits for you.
Moving money? Sending a batch email to current clients? It stops and waits for your explicit approval before taking action.
“Email the Q2 statement to the client.”
waiting for your OK
The orchestrator

Decides what to do, and keeps a record.

Holds your policies, credentials, and context. Logs down its decisions.

The runtime

Does the actual work.

Works in its own locked-down desktop, one task at a time. It can suggest, but never decide.

Security & trust at a glance

The short version, for your security folks.

TopicSummary
Hosting & residencyAmazon Web Services (AWS), region us-east-2 (Ohio). All data resides in the United States, inside Zomma’s virtual private cloud (VPC).
EncryptionEncrypted in transit (TLS 1.2+) and at rest (AES-256).
Model trainingYour data is not used to train Zomma’s or any provider’s foundation models.
CredentialsApplication logins are entered in a secure prompt, stored encrypted in a dedicated vault, never shown in chat, and never sent to an AI model. 1Password integration is currently supported.
Agent actionsActions run through policy checks, with human authorization for sensitive steps and full audit logs. Read- and draft-only scope available.
Access controlPer-organization tenant isolation, SSO/SAML via WorkOS, role-based access, immutable audit trail.
ComplianceGDPR/CCPA-aligned data handling. SOC 2 Type II certification is pending.
Your IT department asked

Straight answers to the common questions.

Is data access read-only, or can agents change things?

Zomma can both read and make changes, but it can’t change anything on its own. Every change is checked against your rules, anything that leaves your systems needs a person to approve it, and all of it is logged. If you prefer, we can set it up to read-only or draft-only, so it never makes a change at all.

Where is the data stored?

All data resides within Zomma’s private AWS environment in us-east-2 (US East / Ohio), with encrypted storage at rest and in transit. Sensitive credentials are kept in an isolated vault, and our cloud desktops are wiped clean after every session.

For your security team

Bring your reviewer. We'll answer everything.

A 30-minute walkthrough of our controls, architecture, and audit trail, with your security lead in the room.

  • Data Processing Agreement (DPA), if required
  • Our full sub-processor list
  • SOC 2 Type II certification timelines
  • A technical walkthrough of how it works
  • Answers to your security questionnaires

Raise what your team can do.