Legal

Security Policy

Understand Zoiko Sema's security program, access controls, data protection practices, incident response, and shared responsibilities between Zoiko Sema and customers.

1.Overview

This Security Policy describes the security program, controls, and shared responsibilities that protect the Zoiko Sema platform and the data processed within it.

2.Security Program Scope

Our security program covers identity and access management, data protection, application security, infrastructure security, monitoring, and incident response across the Service.

3.Access Controls and Identity

Zoiko Sema supports single sign-on (SAML/OIDC), multi-factor authentication, role-based access control, and session management to help organizations control who can access their workspace.

Configure identity and access settings.View Admin Console

4.Customer and Admin Responsibilities

Workspace owners and admins are responsible for configuring user access, roles, guest permissions, retention policies, integrations, and AI governance settings appropriate to their organization's risk profile.

5.Data Protection and Governance

Data protection practices include encryption in transit, access-controlled storage, retention configuration, and export controls, as described in more detail in our Data Processing Addendum.

Review data processing and protection terms.View DPA

6.Meeting, AI, and Workspace Security

Meeting security considerations include access controls for joining sessions, recording and caption permissions, and governance over AI-generated summaries and outputs.

Review AI-specific governance rules.Read AI Use Policy

7.Integrations, APIs, and Third Parties

Integrations and API access are governed by admin-approved scopes, OAuth or service account credentials, and audit logging of integration activity.

Review API authentication and scopes.Open Developer Docs

8.Monitoring, Audit, and Logs

We maintain logging and monitoring designed to detect anomalous activity and support incident investigation. Admins can access relevant audit logs for their workspace where plan and role permit.

9.Incident Reporting

Security incidents affecting the Service are communicated through System Status and, where appropriate, direct customer notification in accordance with applicable law and contractual commitments.

Check current incidents and history.View System Status

10.Vulnerability Reporting

If you believe you've discovered a security vulnerability, please report it responsibly using the channel below so our security team can investigate.

Report a Vulnerability — routes to our responsible disclosure process.

11.Enterprise Security Review

Enterprise and procurement teams can request detailed security documentation, questionnaire responses, and review materials through the Trust Center.

Request detailed security materials.Visit Trust Center

12.Changes to This Policy

We may update this policy as our security program evolves. Material changes will be reflected by an updated effective date.

13.Contact Us

Questions about this policy, or security concerns, can be directed to our security team using the contact options below.

Need a security review or DPA for procurement?

Enterprise and regulated customers can request our vendor security packet, review our Trust Center documentation, or execute a Data Processing Addendum.

Contact Sales
ZoikoSema Logo