Security Policy
Understand Zoiko Sema's security program, access controls, data protection practices, incident response, and shared responsibilities between Zoiko Sema and customers.
1.Overview
This Security Policy describes the security program, controls, and shared responsibilities that protect the Zoiko Sema platform and the data processed within it.
2.Security Program Scope
Our security program covers identity and access management, data protection, application security, infrastructure security, monitoring, and incident response across the Service.
3.Access Controls and Identity
Zoiko Sema supports single sign-on (SAML/OIDC), multi-factor authentication, role-based access control, and session management to help organizations control who can access their workspace.
4.Customer and Admin Responsibilities
Workspace owners and admins are responsible for configuring user access, roles, guest permissions, retention policies, integrations, and AI governance settings appropriate to their organization's risk profile.
5.Data Protection and Governance
Data protection practices include encryption in transit, access-controlled storage, retention configuration, and export controls, as described in more detail in our Data Processing Addendum.
6.Meeting, AI, and Workspace Security
Meeting security considerations include access controls for joining sessions, recording and caption permissions, and governance over AI-generated summaries and outputs.
7.Integrations, APIs, and Third Parties
Integrations and API access are governed by admin-approved scopes, OAuth or service account credentials, and audit logging of integration activity.
8.Monitoring, Audit, and Logs
We maintain logging and monitoring designed to detect anomalous activity and support incident investigation. Admins can access relevant audit logs for their workspace where plan and role permit.
9.Incident Reporting
Security incidents affecting the Service are communicated through System Status and, where appropriate, direct customer notification in accordance with applicable law and contractual commitments.
10.Vulnerability Reporting
If you believe you've discovered a security vulnerability, please report it responsibly using the channel below so our security team can investigate.
Report a Vulnerability — routes to our responsible disclosure process.11.Enterprise Security Review
Enterprise and procurement teams can request detailed security documentation, questionnaire responses, and review materials through the Trust Center.
12.Changes to This Policy
We may update this policy as our security program evolves. Material changes will be reflected by an updated effective date.
13.Contact Us
Questions about this policy, or security concerns, can be directed to our security team using the contact options below.
Need a security review or DPA for procurement?
Enterprise and regulated customers can request our vendor security packet, review our Trust Center documentation, or execute a Data Processing Addendum.
Contact Sales