Trust & Security
Your operations data isn't training someone else's model.
How Zening AI handles your data, your customers' data, and the AI providers underneath.
Section 1
Data ownership.
- Your data stays your data. We do not train models on your operational data.
- All processed data is stored in your designated environment — your cloud, our isolated tenant, or a named provider.
- Export or delete on demand. No lock-in.
Section 2
AI provider stack.
We use named, enterprise-grade providers (Anthropic Claude, OpenAI, Google) under business agreements that exclude training-on-input. We can deploy in your cloud account where required (BYOC). For sensitive industries, we offer on-prem and air-gapped options.
Section 3
Human-in-the-loop, by default.
Every AI action that touches money, contracts, or external customers passes through a human review gate. Audit logs of every AI decision are retained.
Section 4
Compliance.
- SOC 2: in progress. [CLIENT TO PROVIDE — Type I / Type II status when available]
- GDPR / CCPA: data subject requests honored within statutory windows.
- Industry-specific: we list relevant frameworks per engagement (e.g., trade compliance, attorney-client privilege protocols).
FAQ
Security FAQ
Where is my data physically stored?
By default, in your designated environment — your cloud, our isolated tenant, or a named provider. We confirm location during the Discovery phase and document it in the agreement.
What happens if I cancel?
You keep your data, models, and configurations. We export everything in a standard format and delete our copies on a schedule you specify.
Who at Zening can access my data?
Only the named engagement team. Access is logged. We do not view production data without an explicit support request from you.
How do you handle a security incident?
Disclosed in writing within 72 hours of detection, with a root-cause analysis to follow. Specific timing and notification steps are codified in the Master Services Agreement.
Can we sign a custom DPA, BAA, or NDA?
Yes. Standard DPA and NDA available. BAA on request for healthcare-adjacent engagements.
Have a security question we didn't cover? Email us at security@zening.ai.
