Security and data protection at Zenning
Zenning connects to the systems your business runs on. This page sets out how we protect that access — what we encrypt, who can reach your data, where it can be hosted, and what we never do with it.
Last updated: August 20, 2026
Where we stand on certifications
Including the one that is not finished yet. We would rather you heard it here than found out when you asked for the report.
Cyber Essentials
Certified against the UK government-backed Cyber Essentials standard.
GDPR
Built to meet GDPR requirements for how personal data is handled and how your people exercise their rights over it.
ISO 27001
Our information security controls are mapped to the ISO 27001 framework. Aligned to the standard, not certified against it.
SOC 2 Type II
Our controls are built and operating against the SOC 2 Type II framework. The independent audit is underway.
What happens to your data
No model training: Your data is never used to train AI models — ours or our providers’.
Zero data retention: We run zero-retention configurations with the model providers that process your prompts, so your prompts and their outputs are not stored by them.
Encryption everywhere: AES-256 at rest and TLS 1.2+ in transit, wherever your data sits or moves.
Access you control: Single sign-on with SCIM provisioning, plus granular permissions restricting apps and workspaces to specific people and AI employees.
Approval before action: Zenning asks for approval before taking sensitive or high-impact actions. You stay in control of what actually gets done.
Round-the-clock monitoring: Hardened infrastructure watched continuously for threats.
Operational security: Confidentiality agreements in place across our staff and our suppliers.
Dedicated data residency: Application data and model inference can both be provisioned in your chosen region — a dedicated deployment, separate from our standard managed service.
Questions reviewers ask us
The things prospective customers and their security teams want settled before they get started.
No. Your data is never used to train AI models — not ours, and not our providers’. We run zero-retention configurations with the model providers that process your prompts, so your prompts and the outputs generated from them are not stored by them either.
You decide. Access is governed by single sign-on with SCIM provisioning, so accounts and roles follow your existing directory. Granular permissions restrict individual apps and workspaces to specific people and specific AI employees, and confidentiality agreements are in place across our staff and our suppliers.
AES-256 at rest and TLS 1.2 or higher in transit, wherever your data sits or moves. The infrastructure it runs on is hardened and monitored continuously for threats.
We are Cyber Essentials certified against the UK government-backed standard, and we are GDPR compliant. Our controls are aligned to ISO 27001, and our SOC 2 Type II controls are built and operating today with the independent audit underway — we say aligned rather than certified for both, because that is what is accurate right now.
Yes. Application data and model inference can both be provisioned in a region you choose, as a dedicated deployment separate from our standard managed service. Talk to us about your residency requirements and we will confirm exactly what a deployment for you would look like.
Yes to GDPR. A Data Processing Agreement is available on Enterprise plans, alongside support for your security review — send us your questionnaire and we will work through it with you.
We publish the full list, covering infrastructure, AI model providers, communications and monitoring, with what each one is used for. You will find it on our sub-processors page at zenning.ai/legal/sub-processors.
Zenning works proactively, but not unsupervised. He asks for approval before taking sensitive or high-impact actions, so you stay in control of what actually gets done on your systems.
Still have questions?
Start for free and put Zenning to work, or book a demo to see what he can do for your team.
Running a security review?
Send us your questionnaire and we will work through it with you. A Data Processing Agreement is available on Enterprise plans. Our full list of sub-processors — infrastructure, AI model providers, and everything else we rely on — is published at sub-processors.
Book A Demo
Speak with an expert to explore the use cases and
benefits of AI