ZoikoDigital
Trust Center

Truth you can inspect. Controls you can verify.

How ZoikoTime protects organization data, keeps time classification deterministic and reviewable, and keeps human authority over consequential decisions — with the scope, status, owner, limitations, and correction history behind every claim recoverable.

Public evidence needs no account, no form, and no marketing consent.

SecurityPrivacyAccessibilitySystem Status

A reviewer inspecting the evidence, scope, and correction history behind a published trust claim

What a Trust Center is not

Not a badge wall. We do not publish certifications, audit opinions, SLAs, uptime percentages, residency promises, or jurisdictional compliance claims without current evidence, scope, dates, owner, and approval.

Binding product invariant

No hidden surveillance tier.

No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.

Time and attendance evidence is not invasive productivity monitoring. ZoikoTime records what work was performed against configured policy — it does not observe how a person uses a device. There is no plan, setting, contract, or enterprise tier that turns this on.

Commitment owner: Trust & Governance · Status: Current · Last reviewed 12 Jul 2026 · Next review 12 Jan 2027

This invariant does not replace your privacy, labor, or consultation obligations. It describes what the product does not collect — nothing more.

Trust, Governance & Assurance

Three Groups, and an Honest Release State on Every Card

Controls, policies, and assurance artifacts are not interchangeable, so they are not grouped together. A destination appears as Current only when it is approved and production-ready — a prepared wireframe does not make a page current.

Trust — what the platform does

Security

Current

Identity, access, encryption, secure development, logging, incident readiness.

Open

Privacy

Current

Data categories, purposes, access, retention, processors, transfers, rights.

Open

Platform Reliability

Evidence-gated

No reliability claim is published without maintained measures, method, and history.

Available when SLO definitions, measurement method, and ownership are complete.

System Status

Current

Live incidents, maintenance, components, and history from the authoritative source.

Open

Governance — how decisions are bounded

Human-in-Command Controls

Current

Where review authority sits, and what a flag is and is not.

Open

Ethical Design Principles

Evidence-gated

Held until owned principles and enforcement evidence are complete.

Principles without enforcement evidence would be decoration.

AI Governance

Current

Approved ML scope, prohibited uses, and the Kairos boundary.

Open

Administrative Controls

Evidence-gated

Held until the control inventory and documentation are complete.

Request via controlled evidence route below.

Assurance — what can be evidenced to a third party

Compliance & Assurance

Evidence-gated

Certifications, mappings, obligations, and controls stay separated — never presented as one thing.

Request access

Works-Council & Consultation

Evidence-gated

Worker communications and consultation materials require legal review before publication.

Request access

Accessibility

Current

Tested scope, methods, known limitations, owner, and correction route.

Open

Data Location & Residency

Evidence-gated

Assessed region by region. There is no blanket global-residency claim.

Request access

The Trust Center is the canonical overview of these three groups — not a fourth pillar competing with them.

Evidence Lifecycle & Claim Status

How a Public Trust Statement Comes to Exist

And how it gets corrected or withdrawn. A status change always creates an attributable history event.

01Define claim
02Assign owner
03Attach evidence
04Review wording & scope
05Approve status & access
06Publish
07Renew, correct, supersede or withdraw

Public claim statuses

CurrentUnder reviewSupersededWithdrawn

Withdrawn evidence does not remain in search results, cards, or structured data as current.

Evidence access levels

PublicControlled accessContractualCustomer-specific

Every item shows claim ID, owner, reviewer, effective date, last reviewed, next review, and limitations.

Words we do not use as badges

“Verified” and “trusted” without a defined verifier and attached evidence. A badge that nobody signed is worth nothing to an evaluator.

Human Authority & Review Rights

A Flag Is Evidence for Review, Not a Decision

Neutral pending-review states, visible source inputs, the policy or rule version, and the reason for a flag — all available to the worker and the authorized reviewer according to role and policy.

Canonical example

“Unverified Exit — Pending Review”

The state describes the record. It does not describe the person, and it never appears as a finding.

  • Explicit paths correction, approval, escalation, and appeal.

  • Human decisions consequential payroll, discipline, employment, or legal outcomes are made by authorized people, outside automatic classification.

  • Never automated guilt, misconduct, payroll outcome, or disciplinary conclusion.

Human-in-Command Controls

Deterministic Classification & AI Governance

Two different mechanisms, kept apart

Deterministic Time Classification

Policy-bound inputs, versioned rules, jurisdiction and context, reviewable outputs. Not labelled AI — because calling a rule engine “AI” invites trust it has not earned.

Approved machine learning

May flag anomalies or signal-quality concerns for human review. It does not determine time categories, compliance, misconduct, payroll, or employment outcomes.

Kairos

Retrieves, summarizes, and explains governed data. Decides nothing.

Not published

No unapproved model-performance metric, bias claim, or autonomous-action language.

Security Evidence Summary

Six Control Categories, Each With Its Limitation Stated

Summaries only. The Security page holds the detail, and controlled artifacts use the request pathway — security language here never implies zero risk.

Control categoryScopeOwnerLast reviewedStatus
Identity & accessPlatform, admin, service identitiesSecurity01 Jul 2026Current
Encryption & key managementIn transit and at restSecurity01 Jul 2026Current
Secure developmentChange control, review, testingEngineering15 Jun 2026Current
Logging & monitoringPlatform and administrative eventsSecurity01 Jul 2026Current
Incident readinessDetection, response, communicationSecurity20 Jun 2026Current
Vendor & processor controlSubprocessor governancePrivacy & Security28 Jun 2026Under review

Internal architecture, secrets, and full control test results are not published. Certification claims appear only with current evidence and approval.Open Security

Privacy & Worker Transparency

Data categories at a decision-useful level

Privacy is not a subset of security, and this page does not collapse the two.

Categories, each with purpose, access roles, retention, processors, transfers, and rights

  • Account and identity data
  • Organization configuration
  • Time and workforce records
  • Device and service metadata
  • Support and security records

Worker transparency

Workers can see the records that describe their work, understand what a status means and which policy version applied, request a correction, and escalate. Those routes are product behavior, not a policy promise.

Cross-linked to the anti-surveillance invariant, because what is not collected is part of the privacy answer.

Subprocessor list, privacy notice, DPA, and request routes appear only when current. No legal conclusions or jurisdictional rights are published without current legal review.

Open Privacy

Accessibility

We target WCAG 2.2 AA and publish the tested journeys, the methods used, the known limitations, the owner, the last-reviewed date, and the correction route.

No perfect-conformance claim

Any product that claims flawless accessibility has not tested honestly. Our known limitations and their remediation status are published alongside the conformance position.

Open Accessibility

Operational transparency

Incidents, maintenance, component state, subscriptions, and history route to the authoritative live status source. This page does not duplicate live state.

No static uptime percentage

A number printed on a marketing page has no source, no scope, and no measurement window. Platform Reliability stays evidence-gated until maintained SLO definitions, measurement method, history, and ownership exist.

Open System Status

Evidence Directory

Search by Question, Not by Jargon

Sorted by current public commitments and operational facts — never by marketing popularity. Withdrawn, unsafe, customer-specific, and unauthorized controlled content is excluded from the index.

TopicEvidence typeProduct scopeAudienceStatusAccess levelOwnerEffective dateLast reviewed

Anti-surveillance invariant

Public

The exact collection prohibition, applying to every tier and configuration.

Claim ID
TC-0001
Owner
Trust & Governance
Reviewed
12 Jul 2026
Status
Current

Limitation: describes non-collection only. Not a compliance conclusion.

Human authority over decisions

Public

Which decisions require an authorized person, and what a flag is not.

Claim ID
TC-0004
Owner
Product governance
Reviewed
04 Jul 2026
Status
Current

Limitation: applies to product behavior, not your internal process design.

Deterministic classification is not AI

Public

Rule-based, versioned, jurisdiction-aware, reviewable — and not branded as AI.

Claim ID
TC-0007
Owner
AI governance
Reviewed
20 Jun 2026
Status
Current

Limitation: approved ML may still flag anomalies for human review.

Data category & retention map

Public

Categories, purposes, access roles, retention, processors, and transfers.

Claim ID
TC-0012
Owner
Privacy
Reviewed
28 Jun 2026
Status
Current

Limitation: residency commitments apply only where contractually operational.

Security control summaries

Controlled

Control detail at review-appropriate depth for security and procurement teams.

Claim ID
TC-0021
Owner
Security
Reviewed
01 Jul 2026
Status
Current

Access: governed request. Full test results are never public.

Accessibility conformance

Public

Tested scope, method, known limitations, and remediation status.

Claim ID
TC-0030
Owner
Accessibility
Reviewed
22 Jun 2026
Status
Current

Limitation: stated per surface. No blanket conformance claim.

Vendor & processor governance

Controlled

Subprocessor governance and oversight approach.

Claim ID
TC-0034
Owner
Privacy & Security
Reviewed
28 Jun 2026
Status
Under review

Under review: wording and scope being reconfirmed. Prior version superseded.

Regional data location

Contractual

Assessed region by region against current contractual position.

Claim ID
TC-0041
Owner
Privacy
Reviewed
Status
Evidence-gated

No blanket global-residency claim exists or will be published.

No result?

Route

If a claim is not here, it is because it is not currently evidenced — not because it is hidden.

Request Security Review

Search terms are never captured as free-text analytics. Controlled-artifact titles and metadata are withheld where even their existence is restricted.

Evidence Detail

Inspect the Scope Behind a Claim Before Opening It

Claim TC-0001 · version 3

Anti-surveillance invariant

Current · Public

Approved wording

“No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.”

Scope

Product
ZoikoTime platform, all modules
Plan / environment
All plans, all environments
Region
All

Excluded scope

Not covered
Customer-operated third-party tools

Outside ZoikoTime control

Not covered
Your legal obligations

Separate assessment

Governance

Owner
Trust & Governance
Reviewer
Privacy, Legal
Effective
12 Jul 2026
Next review
12 Jan 2027

Evidence type

Type
Product invariant
Source
Engineering attestation + product spec
Access
Public

Limitations & gaps

Describes what is not collected. It is not a privacy compliance conclusion, and it does not address obligations arising from how you configure or use the product.

History

Supersedes
v2 · wording clarified
Corrections
0
Withdrawals
None

Related claims

TC-0004 human authority · TC-0007 classification is not AI · TC-0012 data category map.

A detail view never presents a future-dated or expired artifact as current, and never exposes restricted filenames, customer identifiers, or internal control detail.

Controlled Evidence Access

Request Security Review

A governed route to non-public evidence. Identity, purpose, and entitlement determine access level — not your email domain and not a lead score.

Step 1

What are you evaluating?

Step 2

Minimum details

We ask only what is needed to verify entitlement and route your request.

Step 3

Optional context

Please do not include

Worker-level data, credentials, health information, union or representative details, legal strategy, or any other sensitive content. This field is optional and is never required to receive a response.

We do not promise a response time here, because no SLA is approved for this route. Nothing you enter appears in the page address or in analytics.

Request statuses

ReceivedNeeds clarificationUnder reviewApprovedPartially approvedDeclined with reason categoryExpiredWithdrawn

Approved artifacts use secure delivery with expiry, revocation, and audit. There is no automatic disclosure based on email domain alone.

Changes, Corrections & Withdrawals

Trust History, Visible

We do not silently rewrite prior public claims. We also do not preserve unsafe, legally restricted, or materially false content in public history merely for completeness.

Claim / artifactPreviousNewReason categoryEffectiveOwner
TC-0001 anti-surveillance invariantCurrent v2Current v3Wording clarified12 Jul 2026Trust & Governance
TC-0034 vendor & processor governanceCurrent v4Under reviewScope reconfirmation28 Jun 2026Privacy & Security
TC-0019 legacy uptime statementCurrent v1WithdrawnUnsupported measure02 Jun 2026Trust & Governance
TC-0012 data category mapCurrent v5Superseded by v6Category added28 Jun 2026Privacy

Illustrative change log. Emergency removal may precede retrospective publication of the change record.

A correction record shows what changed and whether prior conclusions or contracts are affected. Superseded items route to the current version; withdrawn items state that they are no longer current, and why, at a safe level.

Direct Answers

Eight High-Intent Trust Questions

No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration. There is no plan, setting, or contract that enables it.

Route to the right evidence

Evidence first. A commercial conversation only if you need one.

Security and procurement teams should use the controlled review pathway. Deployment evaluation and existing-customer assistance are separate routes — and none of them gates the public evidence above.

Existing customers:Help CenterEnterprise SupportSystem Status

No lead form before evidence.No preselected consent.No fake urgency.

Public evidence, no account required

Evidence-gated destinations are listed in the trust model above with their honest release state. A prepared page is not a current page.