Security & Governance

The strongest control is architecture.

Most AI security conversations are about trusting a provider’s promises. ZenithAI changes the conversation: when the platform, the models and the knowledge all live inside your own security boundary, the decisive control is structural — and the remaining controls are built into the product.

Sec. 01 Data residency

Your data stays where you put it.

The core platform — chat, models, embeddings, retrieval, computation, document generation and OCR — processes organisational data entirely on infrastructure you control. There is no external model API behind it and no third-party processing of your prompts, documents or knowledge by the core platform.

Alignment with Indian data-protection law. Processing personal and organisational data inside your own infrastructure directly supports data-minimisation, purpose-limitation and localisation objectives — including obligations that apply to data fiduciaries under India’s Digital Personal Data Protection Act, 2023. Your legal team defines the policy; the architecture makes it enforceable.

Sec. 02 Product controls

Controls built into the platform.

SC-01AuthenticationSign-in verified with time-based one-time passwords; optional persistent sessions bounded by an administrator-set expiry; tokens stored hashed, never plain.Enforced
SC-02Role separationAdministrative functions require an authenticated administrator account — API keys and internal calls can never satisfy an admin check.Enforced
SC-03Workspace isolationPrivate to creator until deliberately published; cross-user requests are refused without confirming a workspace even exists.Enforced
SC-04Fail-closed privileged auditAdministrative access to user content is written to a dedicated audit ledger first; if the audit write fails, the content is withheld.Enforced
SC-05Egress visibilityOutbound activity from optional connectors — email sends, web requests — is logged with sensitive-content redaction.Enforced
SC-06Hardened executionAI-generated analysis code runs in a locked-down sandbox: restricted language surface, resource limits, no network, no filesystem reach.Enforced
SC-07Secret hygieneKeys and tokens stored hashed with atomic, corruption-safe writes; a redaction layer screens artifacts and outbound content for secret-like material.Enforced
SC-08API governanceManaged keys with per-key usage tracking, issued and revoked by administrators; transport security enforced at your gateway with TLS.Enforced
SC-09Human-consent gatesConsequential actions — sending an email, placing a call — require explicit, contemporaneous confirmation. The assistant proposes; a person decides.Enforced

Sec. 03 Shared responsibility

Clear lines, honestly drawn.

Because ZenithAI runs in your environment, security is a partnership. We are explicit about which controls the product enforces, which the deployment configures, and which remain yours — so your CISO evaluates a real architecture, not a slogan.

LayerResponsibility
Product controlsEnforced by ZenithAI: authentication, isolation, auditing, sandboxing, consent gates, secret hygiene
Deployment controlsConfigured per engagement with our team: network placement, TLS termination, module enablement, retention, backup
Customer environmentOperated by you: physical security, host OS and network hardening, identity lifecycle, disk encryption policy
Optional connectorsJointly governed: each outward-reaching module is enabled deliberately, scoped and logged

Sec. 04 Governance

Administration with oversight built in.

User overview, API-key management, model and system health, and audited access to user activity when duty requires it — every such access itself recorded in the privileged-access ledger.

Enterprise-defined policy. Which modules are enabled, which workspaces are shared, how long sessions persist, what leaves the network — these are your decisions, expressed as configuration, not requests to a vendor.

ZenithAI does not currently claim third-party security certifications for the product itself; security posture is demonstrated through architecture review and deployment-specific assessment with your team.

The next step

Bring your CISO. We’ll bring the architecture.

We welcome security review as part of every evaluation — walkthrough, data-flow diagrams and control mapping against your framework.