Trust · Security & privacy
Built forconfidential work.
Independent assurance and clear data commitments for legal teams, security reviewers and procurement.
01 · Independent assurance
Audited outside Zeno.
Certifications, independent testing and mapped controls are published so legal, security and procurement teams can inspect the evidence directly.
ISO 27001
Information security management scope and controls.
ISO 27017
Cloud security control scope and implementation.
ISO 27018
Protection of personal data in public cloud services.
GDPR
Data protection controls aligned with GDPR requirements.
Penetration test
The application and infrastructure are assessed through white-box penetration testing.
§ 43e BRAO
Controls for confidentiality, provider selection and professional obligations.
02 · Data commitments
What happens to your data.
The operating commitments behind customer isolation, regional processing and model use—written plainly enough to review.
Inspect the live controls ↗Boundaries
Workspace boundaries
Customer data is not shared with other Zeno customers. Templates and documents remain private unless you share them inside your own organisation.
Purpose limitation
Customer data is used to perform the requested processing, not to improve third-party products or services.
Residency and protection
EU and EEA processing
Zeno’s published Trust Center states that customer data remains within the EU or EEA.
Encryption
Data is encrypted during storage and transmission.
Model use
No model training
Customer data is not used to train Zeno or the underlying AI models.
Abuse monitoring disabled
Abuse monitoring features are disabled in the model environment described in Zeno’s Trust Center.
Retention
Deletion stays final
Uploaded files and templates are not copied or backed up. They remain until you delete them, at which point deletion is permanent.
03 · Procurement questions
The questions teams ask first.
Direct answers for an initial review. The live Trust Center remains the current source for policies, subprocessors and supporting documents.
01Where is customer data processed?
Zeno’s Trust Center states that customer data remains within the EU or EEA and that the large language models used by Zeno are deployed and hosted in the EU.
02Is customer data used to train AI models?
No. Neither Zeno nor the underlying AI models are trained on customer data. Data is processed to perform the request.
03How long are documents kept?
Documents remain for as long as you keep them in your environment. Zeno does not delete them automatically. Uploaded files and templates are not backed up, so deletion is permanent.
04Can another customer see our templates?
No. Templates, documents and knowledge remain private. You can choose to make them visible to other users inside your own organisation.
05What is Zeno’s role under the GDPR?
Zeno acts as processor for personal data uploaded or generated by customers in the service. Zeno acts as controller for account information, usage data and communications needed to operate the platform and manage accounts.
06How are security incidents handled?
Zeno maintains a formal incident-management procedure. If personal data is affected, the published policy is to notify customers without undue delay and no later than 48 hours.
04 · Live record
Review the current evidence.
Use the live sources for the latest controls, availability and legal documents.