Security
CurrentIdentity, access, encryption, secure development, logging, incident readiness.
OpenHow ZoikoTime protects organization data, keeps time classification deterministic and reviewable, and keeps human authority over consequential decisions — with the scope, status, owner, limitations, and correction history behind every claim recoverable.
Public evidence needs no account, no form, and no marketing consent.

What a Trust Center is not
Not a badge wall. We do not publish certifications, audit opinions, SLAs, uptime percentages, residency promises, or jurisdictional compliance claims without current evidence, scope, dates, owner, and approval.
Binding product invariant
No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.
Time and attendance evidence is not invasive productivity monitoring. ZoikoTime records what work was performed against configured policy — it does not observe how a person uses a device. There is no plan, setting, contract, or enterprise tier that turns this on.
Commitment owner: Trust & Governance · Status: Current · Last reviewed 12 Jul 2026 · Next review 12 Jan 2027
This invariant does not replace your privacy, labor, or consultation obligations. It describes what the product does not collect — nothing more.
Trust, Governance & Assurance
Controls, policies, and assurance artifacts are not interchangeable, so they are not grouped together. A destination appears as Current only when it is approved and production-ready — a prepared wireframe does not make a page current.
Identity, access, encryption, secure development, logging, incident readiness.
OpenData categories, purposes, access, retention, processors, transfers, rights.
OpenNo reliability claim is published without maintained measures, method, and history.
Available when SLO definitions, measurement method, and ownership are complete.
Live incidents, maintenance, components, and history from the authoritative source.
OpenWhere review authority sits, and what a flag is and is not.
OpenHeld until owned principles and enforcement evidence are complete.
Principles without enforcement evidence would be decoration.
Approved ML scope, prohibited uses, and the Kairos boundary.
OpenHeld until the control inventory and documentation are complete.
Request via controlled evidence route below.
Certifications, mappings, obligations, and controls stay separated — never presented as one thing.
Request accessWorker communications and consultation materials require legal review before publication.
Request accessTested scope, methods, known limitations, owner, and correction route.
OpenAssessed region by region. There is no blanket global-residency claim.
Request accessThe Trust Center is the canonical overview of these three groups — not a fourth pillar competing with them.
Evidence Lifecycle & Claim Status
And how it gets corrected or withdrawn. A status change always creates an attributable history event.
Withdrawn evidence does not remain in search results, cards, or structured data as current.
Every item shows claim ID, owner, reviewer, effective date, last reviewed, next review, and limitations.
Words we do not use as badges
“Verified” and “trusted” without a defined verifier and attached evidence. A badge that nobody signed is worth nothing to an evaluator.
Human Authority & Review Rights
Neutral pending-review states, visible source inputs, the policy or rule version, and the reason for a flag — all available to the worker and the authorized reviewer according to role and policy.
“Unverified Exit — Pending Review”
The state describes the record. It does not describe the person, and it never appears as a finding.
Explicit paths — correction, approval, escalation, and appeal.
Human decisions — consequential payroll, discipline, employment, or legal outcomes are made by authorized people, outside automatic classification.
Never automated — guilt, misconduct, payroll outcome, or disciplinary conclusion.
Deterministic Classification & AI Governance
Policy-bound inputs, versioned rules, jurisdiction and context, reviewable outputs. Not labelled AI — because calling a rule engine “AI” invites trust it has not earned.
May flag anomalies or signal-quality concerns for human review. It does not determine time categories, compliance, misconduct, payroll, or employment outcomes.
Retrieves, summarizes, and explains governed data. Decides nothing.
No unapproved model-performance metric, bias claim, or autonomous-action language.
Security Evidence Summary
Summaries only. The Security page holds the detail, and controlled artifacts use the request pathway — security language here never implies zero risk.
| Control category | Scope | Owner | Last reviewed | Status |
|---|---|---|---|---|
| Identity & access | Platform, admin, service identities | Security | 01 Jul 2026 | Current |
| Encryption & key management | In transit and at rest | Security | 01 Jul 2026 | Current |
| Secure development | Change control, review, testing | Engineering | 15 Jun 2026 | Current |
| Logging & monitoring | Platform and administrative events | Security | 01 Jul 2026 | Current |
| Incident readiness | Detection, response, communication | Security | 20 Jun 2026 | Current |
| Vendor & processor control | Subprocessor governance | Privacy & Security | 28 Jun 2026 | Under review |
Internal architecture, secrets, and full control test results are not published. Certification claims appear only with current evidence and approval.Open Security
Privacy & Worker Transparency
Privacy is not a subset of security, and this page does not collapse the two.
Workers can see the records that describe their work, understand what a status means and which policy version applied, request a correction, and escalate. Those routes are product behavior, not a policy promise.
Cross-linked to the anti-surveillance invariant, because what is not collected is part of the privacy answer.
Subprocessor list, privacy notice, DPA, and request routes appear only when current. No legal conclusions or jurisdictional rights are published without current legal review.
Open PrivacyWe target WCAG 2.2 AA and publish the tested journeys, the methods used, the known limitations, the owner, the last-reviewed date, and the correction route.
No perfect-conformance claim
Any product that claims flawless accessibility has not tested honestly. Our known limitations and their remediation status are published alongside the conformance position.
Incidents, maintenance, component state, subscriptions, and history route to the authoritative live status source. This page does not duplicate live state.
No static uptime percentage
A number printed on a marketing page has no source, no scope, and no measurement window. Platform Reliability stays evidence-gated until maintained SLO definitions, measurement method, history, and ownership exist.
Evidence Directory
Sorted by current public commitments and operational facts — never by marketing popularity. Withdrawn, unsafe, customer-specific, and unauthorized controlled content is excluded from the index.
The exact collection prohibition, applying to every tier and configuration.
Limitation: describes non-collection only. Not a compliance conclusion.
Which decisions require an authorized person, and what a flag is not.
Limitation: applies to product behavior, not your internal process design.
Rule-based, versioned, jurisdiction-aware, reviewable — and not branded as AI.
Limitation: approved ML may still flag anomalies for human review.
Categories, purposes, access roles, retention, processors, and transfers.
Limitation: residency commitments apply only where contractually operational.
Control detail at review-appropriate depth for security and procurement teams.
Access: governed request. Full test results are never public.
Tested scope, method, known limitations, and remediation status.
Limitation: stated per surface. No blanket conformance claim.
Subprocessor governance and oversight approach.
Under review: wording and scope being reconfirmed. Prior version superseded.
Assessed region by region against current contractual position.
No blanket global-residency claim exists or will be published.
If a claim is not here, it is because it is not currently evidenced — not because it is hidden.
Request Security ReviewSearch terms are never captured as free-text analytics. Controlled-artifact titles and metadata are withheld where even their existence is restricted.
Evidence Detail
Claim TC-0001 · version 3
Anti-surveillance invariant
“No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.”
Outside ZoikoTime control
Separate assessment
Describes what is not collected. It is not a privacy compliance conclusion, and it does not address obligations arising from how you configure or use the product.
TC-0004 human authority · TC-0007 classification is not AI · TC-0012 data category map.
A detail view never presents a future-dated or expired artifact as current, and never exposes restricted filenames, customer identifiers, or internal control detail.
Controlled Evidence Access
A governed route to non-public evidence. Identity, purpose, and entitlement determine access level — not your email domain and not a lead score.
Request statuses
Approved artifacts use secure delivery with expiry, revocation, and audit. There is no automatic disclosure based on email domain alone.
Changes, Corrections & Withdrawals
We do not silently rewrite prior public claims. We also do not preserve unsafe, legally restricted, or materially false content in public history merely for completeness.
| Claim / artifact | Previous | New | Reason category | Effective | Owner |
|---|---|---|---|---|---|
| TC-0001 anti-surveillance invariant | Current v2 | Current v3 | Wording clarified | 12 Jul 2026 | Trust & Governance |
| TC-0034 vendor & processor governance | Current v4 | Under review | Scope reconfirmation | 28 Jun 2026 | Privacy & Security |
| TC-0019 legacy uptime statement | Current v1 | Withdrawn | Unsupported measure | 02 Jun 2026 | Trust & Governance |
| TC-0012 data category map | Current v5 | Superseded by v6 | Category added | 28 Jun 2026 | Privacy |
Illustrative change log. Emergency removal may precede retrospective publication of the change record.
A correction record shows what changed and whether prior conclusions or contracts are affected. Superseded items route to the current version; withdrawn items state that they are no longer current, and why, at a safe level.
Direct Answers
No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration. There is no plan, setting, or contract that enables it.
Route to the right evidence
Security and procurement teams should use the controlled review pathway. Deployment evaluation and existing-customer assistance are separate routes — and none of them gates the public evidence above.
Existing customers:Help CenterEnterprise SupportSystem Status
Evidence-gated destinations are listed in the trust model above with their honest release state. A prepared page is not a current page.