Skip to content
Trust & security

Held to the standard it sells.

ZenReps exists to keep regulated promotion on-label and on the record — so we hold this page to the same discipline. Everything below reflects our current posture, and the status marks are literal — roadmap is marked as roadmap.

01Trust & security

Certifications & posture

The status marks are literal. Each item below is on the active roadmap, sequenced to give customers full trust and compliance assurance in the product.

SOC 2Roadmap
Our architecture is mapped to the SOC 2 control families. Formal Type I scoping begins at first deployment, with Type II to follow within twelve months. No audit is engaged today; status is published here as it progresses.
HIPAA / BAAPosture
We do not solicit patient information, and the agent treats patient-specific questions as out of scope. We will discuss data-protection terms, including a BAA where a deployment calls for one, during procurement.
ISO 42001 (AI management)Intended
On the roadmap as the AI-governance standard matures; not formally pursued today, and status is published here when that changes.
02Trust & security

Assurance roadmap

The posture above, as one table — the same literal status discipline: what ships in the product today, and what is sequenced next. Statuses update here as each item lands.

Assurance itemStatusWhere it stands
Encryption in transit & at restShippedData is encrypted in transit (TLS) and at rest at the database and object-store layer.
Append-only audit loggingShippedAn append-only audit trail with database-level tamper protection records every turn; reconstruct any conversation and export CSV for an inspector.
SOC 2PlannedArchitecture is mapped to the SOC 2 control families; formal Type I scoping begins at first deployment, with Type II to follow within twelve months.
Independent penetration testPlannedIndependent penetration testing is sequenced on the assurance roadmap; the engagement summary is made available to customers under NDA as it completes.
Data processing agreement (DPA)PlannedData-processing terms are agreed as part of each deployment's contract; a standard-form DPA is on the roadmap.

Request security documentation

Security documentation — the subprocessor list with regions and data-flow detail, architecture and verification detail under NDA, and the assurance items above as they progress — is available to prospective customers on request.

03Trust & security

Data handling & residency

Regional residency

Canadian deployments are provisioned in ca-central-1 (Montreal) today; a US region stands up in-region when a US tenant onboards. Processing providers and their regions are listed in the subprocessors registry.

Patient data is minimized, not invited

The text channel is built to avoid protected health information: a ZenRep is instructed not to solicit patient details and treats patient-specific questions as out of scope, and a pattern-based redactor strips common identifier shapes — emails, phone numbers, MRN/SSN-style patterns — where they appear. The verifier grounds only against your approved corpus.

Encryption

Data is encrypted in transit (TLS) and at rest at the database and object-store layer.

Retention & minimization

We keep the auditable record a regulated channel requires, and no more. Per-jurisdiction retention controls — including reduced free-text retention where the law requires it — are on the roadmap.

04Trust & security

Responsible AI

The guardrails are the product, stated as policy:

  • Corpus-bounded — a ZenRep speaks only from your MLR-approved materials; there is no general-model answer underneath.
  • Fail-closed — anything that cannot be grounded is refused, not guessed.
  • Human-in-the-loop — edge cases and adverse-event reports route to your team, never to an autonomous decision.
  • No autonomous medical advice — HCP-facing promotional support only, never diagnosis or treatment direction.
  • No self-directed drift — improvements ship as MLR-approved corpus and templates, under your control.

What a ZenRep will not do — the ledgered list, in MLR language

05Trust & security

Security practices

Access control

Row-level security isolates every tenant; cross-tenant operator access is gated, with access logging on our near-term list.

Audit logging

An append-only audit trail with database-level tamper protection records every turn; reconstruct any conversation and export CSV for an inspector.

Change & vulnerability posture

Compliance-bearing paths ship behind review and automated guards; secret scanning runs in the pipeline, with dependency scanning on the roadmap.

06Trust & security

Subprocessors

We maintain a current list of the infrastructure and model providers that process data on our behalf — cloud hosting and our primary database in the Canadian region, plus model, observability, and transactional-email providers, some of which operate in other regions. We make the itemized list — with each provider's region, BAA status, and data-flow detail — available to prospective customers on request, and we notify customers of material changes.

07Trust & security

Security contact

Responsible-disclosure reports and security questions are welcome: security@zenreps.com.

Bring your security and MLR teams to the table.

A demo runs against a corpus that looks like yours, with your compliance and data questions front and center.