Security and privacy for your firm’s most sensitive deal information. Explore the safeguards we’re developing for Zylox.
Protecting Your Deal Information
Security Built Into Every Layer
Our security team oversees Zylox’s infrastructure, product and operations. Continuous monitoring works alongside SAML single sign-on, audit logging, IP access restrictions and data lifecycle controls to protect sensitive deal information.
Your Data, Under Your Control
Your firm decides what to upload, how long information is retained and when it is deleted. Deployment in supported regions helps you meet your data residency requirements, with hosting and processing arrangements agreed for your environment.
No Training on Your Data
Your documents, questions and generated outputs are not used to train shared AI models. Our contractual commitments set out these protections, with any firm-specific training subject to separate, explicit agreement.
Information Barriers That Follow Your Policies
Zylox enforces your firm’s existing ethical wall policies to restrict access and prevent unauthorised sharing. Your designated policy system remains the authoritative record, while Zylox applies those rules without creating, changing or removing them.
Clear, Accountable Security Commitments
Our Security Addendum defines responsibilities for data protection, access management and incident response. These commitments give your firm a documented basis for assessing our controls and holding us accountable to the agreed requirements.
Independent Security Assessment
External security specialists assess our systems and controls to identify weaknesses, validate safeguards and guide improvements. Their findings provide independent evidence to support your firm’s security review.
Security and Control for Your Firm
We’re working towards enterprise-grade security and compliance for sensitive deal work, including SAML SSO, audit logs, IP allow-listing and data lifecycle management.
In progress
SOC2 II
In progress
ISO 27001
In progress
GDPR
In progress
Security at every stage of the deal
Sensitive transactions call for clear boundaries around information. Our security work focuses on how deal materials are stored, accessed, reviewed and shared.
We’re building the controls and supporting documentation that help your firm assess Zylox against its requirements. Here are the questions guiding that work.
What information does Zylox protect?
Our security work covers uploaded deal documents, the questions your team asks, generated findings and draft outputs, together with workspace and account information. The scope of data handling will be documented in the applicable agreement.
How is deal information kept private?
We’re developing layered safeguards covering authentication, document permissions, workspace isolation and activity records. Our security and assurance initiatives are in progress; confirmed controls should be reviewed with your firm before deployment.
Where will our information be hosted?
Dedicated cloud and VPC deployment options are being developed to accommodate firm-specific requirements. Hosting location, processing arrangements and operational responsibilities will be agreed before deployment.
Who can access documents and shared workspaces?
Our permissions work is designed to let firms define who can access documents, contribute to reviews and share outputs. Workspace and document access should follow the authorisations established by your firm.
Will our information train shared models?
The intended policy is that your documents, questions and outputs are not used to train shared models. Provider commitments and technical safeguards are being established as part of this work.
Can we request a model tailored to our firm?
Firm-specific model work would use explicitly approved datasets and agreed quality standards. Any training scope, data rights and deployment requirements would need to be agreed separately before work begins.
What is the status of audits and certifications?
Our independent testing and certification initiatives are in progress. The standards shown on this page are targets, not completed certifications. Evidence and assessment details will be shared as they become available.