Zeno

Trust is our product

Self-hosted EU infrastructure, zero third-party LLM calls, and GDPR compliance by design — not as an afterthought.

Data Flow

How your data moves

EU DATACENTRESLondon · Brussels · FrankfurtCustomerYour teamSlack · Teams · WebZenoPart of the Zeroramp stackYour sourcesCRM · Docs · KBRegion may vary1 · Request2 · Fetch3 · Context4 · Response

How We Protect You

Security Practices

Encryption at Rest & In Transit

AES-256 at rest. TLS 1.3 in transit.

Self-Hosted EU Infrastructure

All models and data processing run on infrastructure we control within the EU. Your data is never sent to third-party AI providers like OpenAI, Anthropic, or Google.

Data Isolation

Each customer's data is logically isolated in a dedicated tenant. We never use your data to train models or share it across tenants.

Regular Penetration Testing

We conduct regular penetration testing with independent third-party firms and publish summary reports to enterprise customers upon request.

Transparency

Sub-Processors

Current list of third-party processors with access to any customer data.

ProcessorPurposeLocationData Processed
OVHcloudCloud infrastructure & computeBelgium · London · FrankfurtApplication hosting, model inference, data storage
Plausible AnalyticsPrivacy-friendly website analyticsEUAnonymous page views (no cookies, no personal data)
Tally.soTrial signup formsBelgium (EU)Name, email, company (form submissions only)
AttioCRM & customer managementUK / EUContact details, company information
TermlyCookie consent & privacy complianceEUConsent preferences
LeexiCall recording & transcriptionEUCall audio, transcripts, meeting metadata
Stripe Payments Europe LtdPayment processing & subscription billingEU (Ireland)Payment details, billing information, subscription status

Status

Certifications we're pursuing

GDPR is live today. ISO 27001 and SOC 2 Type II are on deck.

GDPR Compliant

Active

Fully compliant with the General Data Protection Regulation from day one. DPA included as standard.

ISO 27001

Q4 2026

Information security management certification. Currently in implementation phase with target certification by Q4 2026.

SOC 2 Type II

2027

Service organization control audit for security, availability, and confidentiality. Planned post ISO 27001.

Roadmap

ISO 27001 Roadmap

Here's exactly how we get to ISO 27001:2022 certification.

Q2 2026In Progress

Gap Analysis

Comprehensive gap analysis against ISO 27001:2022 requirements. ISMS scope defined.

Q3 2026Pending

Policy & Controls Implementation

Drafting all required policies, procedures, and implementing Annex A controls. Risk assessment completed.

Q4 2026Pending

Internal Audit & Certification

Internal audit, management review, and Stage 1 + Stage 2 certification audit with accredited body.

Q4 2026Pending

Surveillance & Continuous Improvement

First surveillance audit cycle. Continuous ISMS improvement and SOC 2 Type II preparation.

Request Our DPA & Security Pack

Get instant access to our signed DPA, data flow diagrams, ISO 27001 commitment, and privacy guarantee — all in one secure Tresorit repository.

Signed DPA (Art. 28 GDPR)Data Flow Diagram (PDF)ISO 27001 CommitmentPrivacy GuaranteePilot SLASub-Processor List