SECURITY

Security as the foundation

Zukko is built to enterprise requirements from day one — banks, airlines, medical networks. AES-256 encryption at rest, TLS 1.3 in transit, RBAC, an audit trail on every action. Deploy in SaaS, private cloud or on-prem — your choice.

A DPA is signed before the demo. Deploy: SaaS, private cloud or on-prem.

AES-256Encryption at restTLS 1.3Encryption in transitUZData residency
DATA PROTECTION

How does Zukko.AI protect data?

Zukko.AI encrypts data with AES-256 at rest and TLS 1.3 in transit, restricts access via RBAC and writes an audit trail on every action. UZ customer data is stored in Uzbekistan. Deploy as SaaS, private cloud or on-prem — your choice.

  • AES-256 at rest · TLS 1.3 in transit
  • RBAC and an audit trail on every action
  • UZ customer data — stored in Uzbekistan

See also:PlatformCall AnalyticsTrust center

SECURITY CONTROLS

What is already in force

Straight talk: we state the controls in force, not certificates

In force

Data inside your perimeter

Deployment is your call: SaaS, private cloud or on-prem. Every user and AI action is written to the audit trail; the pen-test report is available to enterprise customers under NDA.

Ready

GDPR compliant

A DPA is signed before onboarding begins. Sub-processors are documented and available at /trust.

Ready

UZ Data Law

UZ customer data is stored on Uzbek territory. Processing consent is a standard flow in the customer onboarding form.

PRINCIPLES

Six layers of protection

From encryption keys to a quarterly pen-test — we verify every layer on its own

Encryption at rest

AES-256 for the database, file storage and backups. Keys live in an HSM on the customer’s on-prem deployment.

Encryption in transit

TLS 1.3 for all connections between services and client browsers. Certificates via Let’s Encrypt with auto-renewal.

RBAC

Role-based access control with five base roles: Admin, Manager, Operator, Compliance, Viewer. Custom roles on the Enterprise plan.

Audit logs

Every user and AI action is logged with timestamp, IP and user-agent. Retention — 7 years for financial industries, 1 year by default.

Data residency

UZ customers — data never leaves Uzbekistan. EU customers — EU. The region is chosen at DPA signing and changed on request.

Pen-testing

Quarterly pen-test by an external contractor. Report available to enterprise customers under NDA. Critical findings closed within 30 days.

DEMO CALL

Hear the AI agent — it calls you on its own

Leave a number — the demo call runs in Uzbek or Russian.

Get a demo call

It takes 2 minutes — nothing to connect or set up.

FAQ

Frequently asked security questions

What encryption do you use?

AES-256 for data at rest (database, file storage, backups) and TLS 1.3 for data in transit. On an on-prem deployment, encryption keys live in an HSM on the customer side.

Where is our data physically stored?

UZ customer data is stored on Uzbek territory and never leaves it. For EU customers — the EU region. The region is fixed at DPA signing and changed on request.

How do you evidence security?

With controls that are in force, not certificates: AES-256 and TLS 1.3 encryption, role-based access, a full audit trail, quarterly pen-testing and deployment inside your own perimeter. The pen-test report and a completed security questionnaire are available to enterprise customers under NDA on request.

How is employee access controlled?

Role-based access control (RBAC) with five base roles: Admin, Manager, Operator, Compliance, Viewer. Every user and AI action is logged with timestamp, IP and user-agent. Custom roles are available on the Enterprise plan.

Which deployment options do you support?

SaaS, private cloud or on-prem — your choice. SMB go-live starts from 2 hours; an enterprise rollout with private cloud or on-prem — up to 30 days.

Are you a fit for banks and financial organizations?

Yes. Zukko is built to enterprise requirements — CIS banks, airlines, medical networks. Audit-log retention is 7 years for financial industries, with a quarterly pen-test by an external contractor and critical findings closed within 30 days.

SECURITY REVIEW

Ready to pass your security review

We complete the enterprise security questionnaire within 5 business days. The pen-test report and a description of our controls — under NDA on request.

Deploy your way: SaaS, private cloud or on-prem.