Security and trust
Built to be trusted with access.
Zamski reads operating records that a company would not hand to an outside party lightly. The controls below describe how that access is bounded, what Zamski does with what it reads, and what it will not conclude.
Access
Access is granted by the company and scoped to the engagement. The permissions requested for each source are disclosed before connection and recorded in the engagement terms.
Zamski does not modify source-system business records. It does not create, edit, or delete issues, comments, commits, messages, or calendar events. Some sources require an integration-management permission to establish the connection itself, such as registering a webhook. Those permissions are disclosed before connection and are separate from any ability to change business records.
Every read is scoped to the organization that granted access.
Evidence and findings
Every finding resolves to the source records behind it, so the company can check the same evidence the investor is reading.
Findings are preserved with the evidence they were made from. A later review shows what changed. It does not rewrite the earlier finding.
Where the available evidence is not sufficient to conclude, the report states that and draws no conclusion. Absence of expected evidence can support a finding only within the coverage the report states.
Language models
Language models are used only to write findings in plain language from verified evidence. They do not decide what counts as evidence, and they do not determine whether a claim is supported or contradicted. Those decisions are made from structured fields.
Data handling
Encryption
Data is encrypted in transit and at rest. OAuth tokens are encrypted with AES-256-GCM.
Hosting
Hosted on AWS in the United States.
Retention and deletion
Data is deleted at the end of the engagement on request. Retention terms are set in the data processing agreement.
Third parties
Customer data is not sold, and is not shared with third parties beyond the subprocessors named in the trust center.
Agreements
Access terms and a data processing agreement are agreed before any access is granted.
Attestation
SOC 2 Type II attestation, audited by Sensiba LLP. Audit period December 17, 2025 through March 18, 2026. The report is available under NDA at the trust center.
Reporting a vulnerability
Send security reports to [email protected].