Security

Enterprise-grade security and controls.

Where available, Zom shows supporting source information for review. Client data sent to the model provider is processed under zero-data-retention terms and is not used to train third-party models.

AWS InfrastructureEncrypted at RestEncrypted in TransitSecrets Management

Overview

Zom runs on AWS with a defense-in-depth architecture: workloads run in isolated private subnets with no public IPs, data is encrypted at rest and in transit, secrets are managed through AWS Secrets Manager and KMS, and access follows least-privilege, role-based principles. The platform is independently audited against the AICPA SOC 2 Type II framework. Everything on this page exists so your compliance team can verify each of those claims.

Infrastructure & network

Our infrastructure is built on AWS with defense-in-depth principles, ensuring isolation, encrypted communication, and robust network controls.

01

Cloud infrastructure

AWS Fargate on ECS across isolated VPCs with no peering between them. Application and worker tasks run in private subnets with no public IPs.

02

Network isolation

VPC with isolated public and private subnets across separate VPCs with no peering between them. Inbound traffic is filtered by AWS WAF with managed threat rules and rate limiting at the load balancer, and application tasks are never exposed directly to the public internet.

03

Encrypted transport

HTTPS is enforced for every client connection, with all HTTP automatically redirected to HTTPS and TLS 1.2 or higher on every external connection.

04

Container security

Amazon ECR with on-push image scanning enabled. Automated vulnerability detection for all container images.

05

Auto scaling

Intelligent autoscaling policies for CPU and memory ensure optimal performance while maintaining security posture.

06

Logging & monitoring

CloudWatch Logs with 365-day retention. Comprehensive audit trails and real-time monitoring of all infrastructure components.

Data protection

Multi-layered encryption protects your data at rest, in transit, and in use, following industry best practices and compliance standards.

01

Data at rest

All production databases encrypted at rest with AWS managed encryption. Automated backups retained for 7 days with encryption protection.

02

Data in transit

TLS 1.2+ enforced on all external client connections, HTTPS-only, with HSTS headers. Internal service traffic runs entirely within isolated private VPCs with no public exposure and no cross-VPC peering.

03

Secret management

Application secrets and credentials are isolated in AWS Secrets Manager, and encryption keys are protected by AWS KMS, backed by FIPS 140-2 validated hardware security modules (HSMs).

04

Database security

Production PostgreSQL databases run in private subnets and are not publicly accessible. Access is restricted to authorized ECS tasks and optional bastion or VPN connections, with credentials isolated in AWS Secrets Manager and never stored in application code or images.

AI & LLM

Where available, Zom shows supporting source information for review. Client data sent to the model provider is processed under zero-data-retention terms and is not used to train third-party models.

01

Model-provider data controls

Client data sent to the model provider is processed under zero-data-retention terms and is not used to train third-party models.

02

Supporting source information

Where available, Zom shows supporting source information for review.

03

Human review before any action

AI output is prepared for advisor review. Nothing is sent, traded, or acted on until a person approves it.

Application security

Secure by design with authentication, authorization, and input validation built into every layer of our application stack.

01

Authentication & authorization

JWT-based authentication with role-aware access control. API key validation for sensitive endpoints. Password hashing with bcrypt industry-standard algorithms.

02

Input validation

Strongly typed configuration with required field validation. Environment variables validated at startup to prevent misconfiguration.

03

Secret protection

Integration keys and sensitive credentials loaded from environment variables and AWS Secrets Manager. No hardcoded secrets in application code or images.

04

Secure development

Environment files excluded from Docker builds. Secrets managed separately from application code. Type-safe configuration prevents common security pitfalls.

CI/CD & supply chain

Secure deployment pipelines with automated scanning, scoped least-privilege AWS access, and controlled access to production environments.

01

Automated deployment

Deployments run through GitHub Actions with scoped, least-privilege AWS access and no long-lived credentials in application code. Every container image is tagged with its commit SHA for full traceability, and production releases are serialized to prevent overlapping deploys.

02

Image scanning

ECR on-push scanning automatically detects vulnerabilities in container images. Deployment pipeline includes concurrency controls to prevent overlapping production deployments.

Monitoring & operations

Comprehensive monitoring, logging, and health checks ensure we can detect and respond to issues quickly.

01

Centralized logging

CloudWatch Logs with 365-day retention for all application and infrastructure logs. Structured logging enables efficient analysis and alerting.

02

Health monitoring

Application Load Balancer health checks ensure only healthy tasks receive traffic. Automated rollback on deployment failures.

Compliance & governance

Our security controls are designed with compliance in mind, following defense-in-depth and least privilege principles.

SOC 2 trust

Independently audited against the AICPA SOC 2 Type II framework. Review the current report and control details in our Trust Portal.

View our SOC 2 Trust Portal
01

Least privilege

Access is limited to only those with legitimate business need and granted based on the principle of least privilege.

02

Defense in depth

Security controls are implemented and layered according to the principle of defense-in-depth across all systems.

03

Consistent controls

Security controls are applied consistently across all areas of the enterprise, ensuring uniform protection.

Advisor control

01

It does not send communications

Zom never auto-sends client emails or messages. It drafts them for review, and the advisor decides what goes out.

02

It does not execute trades

Zom can surface drift, concentration, and tax-aware rebalancing considerations. It never places a trade.

03

It does not move money

No transfer, disbursement, or money movement happens through Zom. Those actions stay with the advisor and the custodian.

04

It does not replace fiduciary judgment

Zom prepares work product and documents activity. The advisor remains responsible for what is recommended, approved, and implemented.

Records and reviewability

01

Query and response history

A preserved record of what was asked and what the system returned, supporting books-and-records obligations.

02

Advice and communications

A searchable record of advice, communications, AI outputs, and IPS alignment across the relationship.

03

Supporting source information

Where available, Zom shows supporting source information for review.

04

Advisor review documented

A clear record of what was reviewed, generated, approved, and acted on, with exception handling captured.

Regulatory alignment

What we build around

Reference 01
Fiduciary duty stays with the advisor
Reference 02
SEC Marketing Rule
Reference 03
Books and records (Rule 204-2)
Reference 04
Reg S-P privacy and vendor oversight
Reference 05
SEC examination focus on AI

Deadlines that matter

In effect
SEC Marketing Rule and Reg S-P obligations for larger advisers.
June 3, 2026
Reg S-P amendments compliance deadline for smaller advisers.
Ongoing
SEC examination focus on AI usage, disclosures, governance, and cybersecurity.

Vulnerability disclosure program (VDP)

Zom Technologies LLC welcomes responsible security research. If you believe you have found a security vulnerability in our products or services, please report it to us so we can investigate and remediate.

Program overview

Zom operates a public Vulnerability Disclosure Program (VDP) with discretionary rewards, which is appropriate for our current stage and supports the vulnerability disclosure process firms expect during security review.

Report a vulnerability

Email

Please include: affected URL or component, steps to reproduce, impact, and any screenshots/logs.

Program rules

  • Follow responsible disclosure practices
  • Do not access or modify user data without explicit permission
  • Do not perform denial-of-service attacks or any testing that impacts availability
  • Do not publicly disclose vulnerabilities until we have confirmed a fix or agreed on a timeline
  • Only test systems and assets explicitly listed in the "In Scope" section
  • Report vulnerabilities promptly after discovery

In scope

  • ZOM production web application(s)
  • ZOM public API endpoints

Out of scope

  • Denial-of-service (DoS/DDoS), load testing, or any activity that degrades availability
  • Social engineering (phishing, vishing), employee targeting, or physical attacks
  • Testing of third-party systems not owned or controlled by ZOM
  • Automated scanning that materially impacts performance
  • Physical security vulnerabilities
  • Issues requiring access to physical devices or local network access

Safe harbor

If you make a good-faith effort to follow this policy, avoid privacy violations, avoid service disruption, and report vulnerabilities promptly, Zom will not pursue legal action against you for your security research.

Our response commitment

1Acknowledge receipt within 2 business days
2Provide initial triage within 5 business days
3Work toward remediation based on severity and risk

Public disclosure

We request coordinated disclosure. Please do not publicly disclose vulnerabilities until we have confirmed a fix or agreed on a timeline.

Rewards & program structure

Program Type: Vulnerability Disclosure Program (VDP)

This is a VDP, not a formal bug bounty program. There are no predefined reward tiers, minimum payouts, or platform listings, and no guaranteed monetary compensation for reports.

Discretionary rewards

Zom may, at its discretion, offer non-monetary recognition or monetary rewards for high-impact vulnerability reports based on:

  • Severity of the vulnerability (Critical, High, Medium, Low)
  • Quality and completeness of the vulnerability report
  • Exploitability and potential impact
  • Compliance with program rules and responsible disclosure practices

All rewards are discretionary, not guaranteed, and determined on a case-by-case basis.

FAQ

Does using AI violate my fiduciary duty?

No. The advisor remains responsible for the advice, regardless of the tools used to generate it. Zom surfaces data and prepares work product. The advisor makes the final decision.

What if the AI gives wrong information?

Zom pulls from connected firm systems such as CRM, custodian, planning, portfolio, and compliance records. Human review remains required before action, and Zom keeps an audit trail of query and response history.

Do we need to disclose that we use AI?

If AI use is material to how the firm delivers services, it should be reflected accurately in Form ADV Part 2A and related disclosures. Do not overstate what the platform does or understate its use.

What about Reg S-P?

Zom supports privacy and vendor oversight expectations through access controls, encryption, model-provider data controls, and contractual breach-notification practices.

What about recordkeeping under Rule 204-2?

AI-generated output transmitted to a client or used in an investment recommendation should be retained. Zom is designed to maintain exportable audit trails of queries and responses.

Can we use AI-generated content in client communications?

Yes, if the content is reviewed for accuracy and approved before use. Zom does not auto-send client communications.

What is the SEC examining in relation to AI?

Core areas include AI usage matching disclosures, governance, cybersecurity, employee training, privacy controls, and books-and-records practices.

Zom does not replace fiduciary judgment. It does not send client communications, execute trades, move money, or make final recommendations on its own. The advisor decides what reaches the client.

View our live trust center