Held to the standard it sells.
ZenReps exists to keep regulated promotion on-label and on the record — so we hold this page to the same discipline. Everything below reflects our current posture, and the status marks are literal — roadmap is marked as roadmap.
Certifications & posture
The status marks are literal. Each item below is on the active roadmap, sequenced to give customers full trust and compliance assurance in the product.
- SOC 2
- Our architecture is mapped to the SOC 2 control families. Formal Type I scoping begins at first deployment, with Type II to follow within twelve months. No audit is engaged today; status is published here as it progresses.
- HIPAA / BAA
- We do not solicit patient information, and the agent treats patient-specific questions as out of scope. We will discuss data-protection terms, including a BAA where a deployment calls for one, during procurement.
- ISO 42001 (AI management)
- On the roadmap as the AI-governance standard matures; not formally pursued today, and status is published here when that changes.
Assurance roadmap
The posture above, as one table — the same literal status discipline: what ships in the product today, and what is sequenced next. Statuses update here as each item lands.
| Assurance item | Status | Where it stands |
|---|---|---|
| Encryption in transit & at rest | Data is encrypted in transit (TLS) and at rest at the database and object-store layer. | |
| Append-only audit logging | An append-only audit trail with database-level tamper protection records every turn; reconstruct any conversation and export CSV for an inspector. | |
| SOC 2 | Architecture is mapped to the SOC 2 control families; formal Type I scoping begins at first deployment, with Type II to follow within twelve months. | |
| Independent penetration test | Independent penetration testing is sequenced on the assurance roadmap; the engagement summary is made available to customers under NDA as it completes. | |
| Data processing agreement (DPA) | Data-processing terms are agreed as part of each deployment's contract; a standard-form DPA is on the roadmap. |
Request security documentation
Security documentation — the subprocessor list with regions and data-flow detail, architecture and verification detail under NDA, and the assurance items above as they progress — is available to prospective customers on request.
Data handling & residency
Regional residency
Canadian deployments are provisioned in ca-central-1 (Montreal) today; a US region stands up in-region when a US tenant onboards. Processing providers and their regions are listed in the subprocessors registry.
Patient data is minimized, not invited
The text channel is built to avoid protected health information: a ZenRep is instructed not to solicit patient details and treats patient-specific questions as out of scope, and a pattern-based redactor strips common identifier shapes — emails, phone numbers, MRN/SSN-style patterns — where they appear. The verifier grounds only against your approved corpus.
Encryption
Data is encrypted in transit (TLS) and at rest at the database and object-store layer.
Retention & minimization
We keep the auditable record a regulated channel requires, and no more. Per-jurisdiction retention controls — including reduced free-text retention where the law requires it — are on the roadmap.
Responsible AI
The guardrails are the product, stated as policy:
- Corpus-bounded — a ZenRep speaks only from your MLR-approved materials; there is no general-model answer underneath.
- Fail-closed — anything that cannot be grounded is refused, not guessed.
- Human-in-the-loop — edge cases and adverse-event reports route to your team, never to an autonomous decision.
- No autonomous medical advice — HCP-facing promotional support only, never diagnosis or treatment direction.
- No self-directed drift — improvements ship as MLR-approved corpus and templates, under your control.
What a ZenRep will not do — the ledgered list, in MLR language
Security practices
Access control
Row-level security isolates every tenant; cross-tenant operator access is gated, with access logging on our near-term list.
Audit logging
An append-only audit trail with database-level tamper protection records every turn; reconstruct any conversation and export CSV for an inspector.
Change & vulnerability posture
Compliance-bearing paths ship behind review and automated guards; secret scanning runs in the pipeline, with dependency scanning on the roadmap.
Subprocessors
We maintain a current list of the infrastructure and model providers that process data on our behalf — cloud hosting and our primary database in the Canadian region, plus model, observability, and transactional-email providers, some of which operate in other regions. We make the itemized list — with each provider's region, BAA status, and data-flow detail — available to prospective customers on request, and we notify customers of material changes.
Security contact
Responsible-disclosure reports and security questions are welcome: security@zenreps.com.
Bring your security and MLR teams to the table.
A demo runs against a corpus that looks like yours, with your compliance and data questions front and center.