ZoikoDigital
Trust Center

Public evidence, available without a form

Current public security, privacy, governance and accessibility evidence is available here directly. Controlled and customer-specific artifacts may require an approved access process — but public evidence is never withheld to capture a lead.

Public evidence directory

Every record answers the same five questions before it asks anything of you: what is this, what does it cover, how current is it, who owns it, and what does it not prove?

SecurityPrivacyGovernanceAIAccessibilityReliabilityProcurementStatusAccess levelOwnerLast reviewed

Security control-domain summary

Public

Control summary · Security

Scope
Core platform, production environment
Status
Current
Owner
Security & Trust Governance
Effective
01 Jun 2026
Last reviewed
01 Jul 2026
Next review
01 Jan 2027
Does not prove

Describes approved control domains and their status. It is not a certification, a penetration-test result, or evidence about your configuration.

Data-flow overview

Public summary

Architecture summary · Security

Scope
Platform data categories and movement
Status
Current
Owner
Platform architecture
Effective
12 May 2026
Last reviewed
12 May 2026
Next review
Restricted detail not published

Topology, addresses, credentials, and tenant-level configuration are excluded by policy. A public-safe summary only.

Anti-surveillance data boundary

Public

Policy / principle · Privacy

Scope
All tiers and configurations
Status
Current
Owner
Product governance
Effective
01 Jan 2026
Last reviewed
22 Jun 2026
Next review
22 Dec 2026
Does not prove

States a binding product boundary. It is not a legal compliance conclusion for your jurisdiction.

Security testing approach

Public summary

Assurance artifact · Security

Scope
Approach and cadence only
Status
Under review
Owner
Security
Effective
Last reviewed
01 Jul 2026
Next review
Under review — do not treat as current

Currency and scope are being re-evaluated. No exploitable detail is published, and no current test result is implied.

Review ongoing

Independent assurance artifact

Controlled access

Assurance artifact · Security

Scope
Stated in the artifact
Status
Controlled
Owner
Security & Trust Governance
Effective
Per artifact
Last reviewed
01 Jul 2026
Next review
Why this is not public

Contains detail that is not approved for public disclosure. No preview of restricted content is shown, and no issuer name or logo appears without current verified evidence.

Accessibility conformance summary

Public

Accessibility artifact · Accessibility

Scope
Tested journeys, per platform
Status
Current
Owner
Accessibility
Effective
22 Jun 2026
Last reviewed
22 Jun 2026
Next review
22 Dec 2026
Does not prove

Conformance is stated per journey and platform, with known limitations published. It is not a platform-wide claim.

Questionnaire response library

Customer-specific

Contractual resource · Procurement

Scope
Per engagement
Status
Not public
Owner
Procurement & Legal
Effective
Last reviewed
Next review
Why this is not public

Questionnaire responses are engagement-specific and are never published as a searchable answer set. Routed through the approved procurement pathway.

Legacy “enterprise-grade security” claim

Withdrawn

Correction notice · Security

Withdrawn
02 Jun 2026
Reason
Unsupported — no defined scope or evidence
Owner
Trust & Governance
Replacement
Security control-domain summary
Excluded from current results

The positive claim has been removed from evidence listings, search, and structured data. This neutral withdrawal notice remains for transparency.

Operational status & incident history

Public

Operational record · Reliability

Scope
Current operational state
Status
Current — live
Owner
Platform operations
Effective
Continuous
Last reviewed
Live
Next review
Different kind of truth

System Status is authoritative for live operational state. It is not a substitute for security evidence, and security evidence never overrides it.

Default results prioritize current public items. Superseded and withdrawn records are excluded from current listings and from structured data. Search covers approved public metadata only — search terms are never captured in analytics or routed to sales.

Four access classes, ten evidence states

Access level and status are different axes. A record can be Public and Under Review at the same time, and neither implies the other.

Access
Publicfull approved resource availablePublic summaryrestricted detail not publishedControlled accessgoverned review or entitlement requiredCustomer-specificrouted through an approved pathway
StatusMeaningRequired public behaviour
CurrentApproved evidence is current for the displayed scope.Show scope, owner, relevant dates, and limitations.
Under reviewCurrency or scope is being re-evaluated.Do not present as current. Explain that review is ongoing.
SupersededA newer approved version replaces this one.Show the replacement; remove from default current results.
WithdrawnThe artifact or claim is no longer public or current.Remove the positive claim; show a neutral withdrawal notice where approved.
ExpiredThe validity or effective period has ended.Never usable as current assurance.
Unavailable / cannot verifyThe current state cannot be verified.Say so, or suppress the claim. Never default to a positive status.
Semantics law

A public evidence record proves only what its stated type, scope, period, method or authority, status, and limitations support. “Current” does not mean globally secure, compliant with every law, suitable for every deployment, or effective in every customer configuration.

Why some evidence is not public

Not withheld to create friction — withheld because publishing it would itself create risk, or because it belongs to a specific engagement.

Evidence classPublic treatmentWhat must never happen
Security overviewOpen public summary with scope and review date.Turning a summary into a certification or penetration-test claim.
High-level control domainsApproved descriptions and status only.Exposing sensitive configurations, rules, thresholds, or secrets.
Independent assuranceExact verified name, scope, period, and status — only when current.A logo without evidence, or a scope broader than the report supports.
Penetration / security testingApproved approach or public summary only.Exploitable detail, or implying a current test when the summary is stale.
Architecture / data flowPublic-safe summary.Restricted topology, addresses, credentials, tenant or customer data.
Internal policiesPublic only where specifically approved.Accidental document indexing.
Questionnaire responsesNot public — engagement-specific.A searchable public answer dump.
Incident-specific evidenceGoverned through status and support.Routing live incident detail through a marketing Trust Center.
DPA / subprocessorsRouted to their existing legal and privacy authorities.Duplicating a stale legal list on Security or the Trust Center.

When evidence cannot be shown

The governing rule: never a blank directory, never a default-green card, and never a fallback to a sales form.

Evidence service unavailable

“Public evidence is temporarily unavailable. Security information and related Trust pages remain available.” With retry, plus Security, Status, and Help routes.

Never a blank directory or default-green cards.

A specific item is unavailable

Explain that the item is unavailable or moved, and show the current replacement where one is approved.

Never a bare 404, and never an unrelated substitute document.

Review due

Show the review-due or under-review status and the current limitation.

Never a “Current” badge held indefinitely.

Superseded or withdrawn

Show the replacement and preserve history where governance permits; remove withdrawn claims from positive listings.

Never let a stale claim persist in cache or schema.

Controlled request service down

Public evidence stays usable; the request route shows as unavailable with existing support and procurement fallbacks.

Never email confidential files as an insecure workaround.

No JavaScript

Trust content, evidence metadata, links, and public files are server-rendered and remain usable.

Public evidence is never hidden behind a client-only application.

After the evidence, not before it

Need something that is not published here?

Controlled and customer-specific artifacts require an approved access process — identity, purpose, and entitlement — because of what they contain, not because of the sales opportunity. Public evidence above stays open either way.

Get Demo
A reviewer at a desk considering a request routed through approved channels rather than a sales form

Evidence access questions

No. Public evidence is available in the Trust Center without submitting a security-review form, and without an account, login, or chat gate. Controlled and customer-specific artifacts may require an approved access process — but public evidence is never withheld to capture a lead.