SECURITY

Security as the foundation

Zukko is built to enterprise requirements from day one — banks, airlines, medical networks. AES-256 encryption at rest, TLS 1.3 in transit, RBAC, an audit trail on every action. Deploy in SaaS, private cloud or on-prem — your choice.

A DPA is signed before the demo. Deploy: SaaS, private cloud or on-prem.

AES-256Encryption at restTLS 1.3Encryption in transitUZData residency
DATA PROTECTION

How does Zukko.AI protect data?

Zukko.AI encrypts data with AES-256 at rest and TLS 1.3 in transit, restricts access via RBAC and writes an audit trail on every action. UZ customer data is stored in Uzbekistan. Deploy as SaaS, private cloud or on-prem — your choice.

  • AES-256 at rest · TLS 1.3 in transit
  • RBAC and an audit trail on every action
  • UZ customer data — stored in Uzbekistan

See also:PlatformCall AnalyticsTrust center

CERTIFICATIONS

Where we stand on compliance

Straight talk on status. We don’t claim a certificate as held until the audit is complete

In progress · Q4 2026

SOC 2 Type II

Audit in progress. Completion — Q4 2026. Auditor: a Big Four firm in UZ. Report available to enterprise customers under NDA.

Ready

GDPR compliant

A DPA is signed before onboarding begins. Sub-processors are documented and available at /trust.

Ready

UZ Data Law

UZ customer data is stored on Uzbek territory. Processing consent is a standard flow in the customer onboarding form.

PRINCIPLES

Six layers of protection

From encryption keys to a quarterly pen-test — we verify every layer on its own

Encryption at rest

AES-256 for the database, file storage and backups. Keys live in an HSM on the customer’s on-prem deployment.

Encryption in transit

TLS 1.3 for all connections between services and client browsers. Certificates via Let’s Encrypt with auto-renewal.

RBAC

Role-based access control with five base roles: Admin, Manager, Operator, Compliance, Viewer. Custom roles on the Enterprise plan.

Audit logs

Every user and AI action is logged with timestamp, IP and user-agent. Retention — 7 years for financial industries, 1 year by default.

Data residency

UZ customers — data never leaves Uzbekistan. EU customers — EU. The region is chosen at DPA signing and changed on request.

Pen-testing

Quarterly pen-test by an external contractor. Report available to enterprise customers under NDA. Critical findings closed within 30 days.

See how the AI takes your customer from a message to a booking

We build a demo on your real conversations from Instagram, Telegram and telephony — see on your own data how much of an admin’s shift the AI covers, with no CRM rewrite.

FAQ

Frequently asked security questions

What encryption do you use?

AES-256 for data at rest (database, file storage, backups) and TLS 1.3 for data in transit. On an on-prem deployment, encryption keys live in an HSM on the customer side.

Where is our data physically stored?

UZ customer data is stored on Uzbek territory and never leaves it. For EU customers — the EU region. The region is fixed at DPA signing and changed on request.

Do you have SOC 2?

A SOC 2 Type II audit is in progress, completing in Q4 2026. Until the audit is complete we don’t claim the certificate as held. SOC 2 letter and pen-test report are available to enterprise customers under NDA on request.

How is employee access controlled?

Role-based access control (RBAC) with five base roles: Admin, Manager, Operator, Compliance, Viewer. Every user and AI action is logged with timestamp, IP and user-agent. Custom roles are available on the Enterprise plan.

Which deployment options do you support?

SaaS, private cloud or on-prem — your choice. SMB go-live starts from 2 hours; an enterprise rollout with private cloud or on-prem — up to 30 days.

Are you a fit for banks and financial organizations?

Yes. Zukko is built to enterprise requirements — CIS banks, airlines, medical networks. Audit-log retention is 7 years for financial industries, with a quarterly pen-test by an external contractor and critical findings closed within 30 days.

SECURITY REVIEW

Ready to pass your security review

We complete the enterprise security questionnaire within 5 business days. SOC 2 letter and pen-test report — under NDA on request.

Deploy your way: SaaS, private cloud or on-prem.