Cloud infrastructure
AWS Fargate on ECS across isolated VPCs with no peering between them. Application and worker tasks run in private subnets with no public IPs.
Security
Where available, Zom shows supporting source information for review. Client data sent to the model provider is processed under zero-data-retention terms and is not used to train third-party models.
Zom runs on AWS with a defense-in-depth architecture: workloads run in isolated private subnets with no public IPs, data is encrypted at rest and in transit, secrets are managed through AWS Secrets Manager and KMS, and access follows least-privilege, role-based principles. The platform is independently audited against the AICPA SOC 2 Type II framework. Everything on this page exists so your compliance team can verify each of those claims.
Our infrastructure is built on AWS with defense-in-depth principles, ensuring isolation, encrypted communication, and robust network controls.
AWS Fargate on ECS across isolated VPCs with no peering between them. Application and worker tasks run in private subnets with no public IPs.
VPC with isolated public and private subnets across separate VPCs with no peering between them. Inbound traffic is filtered by AWS WAF with managed threat rules and rate limiting at the load balancer, and application tasks are never exposed directly to the public internet.
HTTPS is enforced for every client connection, with all HTTP automatically redirected to HTTPS and TLS 1.2 or higher on every external connection.
Amazon ECR with on-push image scanning enabled. Automated vulnerability detection for all container images.
Intelligent autoscaling policies for CPU and memory ensure optimal performance while maintaining security posture.
CloudWatch Logs with 365-day retention. Comprehensive audit trails and real-time monitoring of all infrastructure components.
Multi-layered encryption protects your data at rest, in transit, and in use, following industry best practices and compliance standards.
All production databases encrypted at rest with AWS managed encryption. Automated backups retained for 7 days with encryption protection.
TLS 1.2+ enforced on all external client connections, HTTPS-only, with HSTS headers. Internal service traffic runs entirely within isolated private VPCs with no public exposure and no cross-VPC peering.
Application secrets and credentials are isolated in AWS Secrets Manager, and encryption keys are protected by AWS KMS, backed by FIPS 140-2 validated hardware security modules (HSMs).
Production PostgreSQL databases run in private subnets and are not publicly accessible. Access is restricted to authorized ECS tasks and optional bastion or VPN connections, with credentials isolated in AWS Secrets Manager and never stored in application code or images.
Where available, Zom shows supporting source information for review. Client data sent to the model provider is processed under zero-data-retention terms and is not used to train third-party models.
Client data sent to the model provider is processed under zero-data-retention terms and is not used to train third-party models.
Where available, Zom shows supporting source information for review.
AI output is prepared for advisor review. Nothing is sent, traded, or acted on until a person approves it.
Secure by design with authentication, authorization, and input validation built into every layer of our application stack.
JWT-based authentication with role-aware access control. API key validation for sensitive endpoints. Password hashing with bcrypt industry-standard algorithms.
Strongly typed configuration with required field validation. Environment variables validated at startup to prevent misconfiguration.
Integration keys and sensitive credentials loaded from environment variables and AWS Secrets Manager. No hardcoded secrets in application code or images.
Environment files excluded from Docker builds. Secrets managed separately from application code. Type-safe configuration prevents common security pitfalls.
Secure deployment pipelines with automated scanning, scoped least-privilege AWS access, and controlled access to production environments.
Deployments run through GitHub Actions with scoped, least-privilege AWS access and no long-lived credentials in application code. Every container image is tagged with its commit SHA for full traceability, and production releases are serialized to prevent overlapping deploys.
ECR on-push scanning automatically detects vulnerabilities in container images. Deployment pipeline includes concurrency controls to prevent overlapping production deployments.
Comprehensive monitoring, logging, and health checks ensure we can detect and respond to issues quickly.
CloudWatch Logs with 365-day retention for all application and infrastructure logs. Structured logging enables efficient analysis and alerting.
Application Load Balancer health checks ensure only healthy tasks receive traffic. Automated rollback on deployment failures.
Our security controls are designed with compliance in mind, following defense-in-depth and least privilege principles.
Independently audited against the AICPA SOC 2 Type II framework. Review the current report and control details in our Trust Portal.
View our SOC 2 Trust PortalAccess is limited to only those with legitimate business need and granted based on the principle of least privilege.
Security controls are implemented and layered according to the principle of defense-in-depth across all systems.
Security controls are applied consistently across all areas of the enterprise, ensuring uniform protection.
Zom never auto-sends client emails or messages. It drafts them for review, and the advisor decides what goes out.
Zom can surface drift, concentration, and tax-aware rebalancing considerations. It never places a trade.
No transfer, disbursement, or money movement happens through Zom. Those actions stay with the advisor and the custodian.
Zom prepares work product and documents activity. The advisor remains responsible for what is recommended, approved, and implemented.
A preserved record of what was asked and what the system returned, supporting books-and-records obligations.
A searchable record of advice, communications, AI outputs, and IPS alignment across the relationship.
Where available, Zom shows supporting source information for review.
A clear record of what was reviewed, generated, approved, and acted on, with exception handling captured.
Zom Technologies LLC welcomes responsible security research. If you believe you have found a security vulnerability in our products or services, please report it to us so we can investigate and remediate.
Zom operates a public Vulnerability Disclosure Program (VDP) with discretionary rewards, which is appropriate for our current stage and supports the vulnerability disclosure process firms expect during security review.
Please include: affected URL or component, steps to reproduce, impact, and any screenshots/logs.
If you make a good-faith effort to follow this policy, avoid privacy violations, avoid service disruption, and report vulnerabilities promptly, Zom will not pursue legal action against you for your security research.
We request coordinated disclosure. Please do not publicly disclose vulnerabilities until we have confirmed a fix or agreed on a timeline.
This is a VDP, not a formal bug bounty program. There are no predefined reward tiers, minimum payouts, or platform listings, and no guaranteed monetary compensation for reports.
Zom may, at its discretion, offer non-monetary recognition or monetary rewards for high-impact vulnerability reports based on:
All rewards are discretionary, not guaranteed, and determined on a case-by-case basis.
No. The advisor remains responsible for the advice, regardless of the tools used to generate it. Zom surfaces data and prepares work product. The advisor makes the final decision.
Zom pulls from connected firm systems such as CRM, custodian, planning, portfolio, and compliance records. Human review remains required before action, and Zom keeps an audit trail of query and response history.
If AI use is material to how the firm delivers services, it should be reflected accurately in Form ADV Part 2A and related disclosures. Do not overstate what the platform does or understate its use.
Zom supports privacy and vendor oversight expectations through access controls, encryption, model-provider data controls, and contractual breach-notification practices.
AI-generated output transmitted to a client or used in an investment recommendation should be retained. Zom is designed to maintain exportable audit trails of queries and responses.
Yes, if the content is reviewed for accuracy and approved before use. Zom does not auto-send client communications.
Core areas include AI usage matching disclosures, governance, cybersecurity, employee training, privacy controls, and books-and-records practices.
Zom does not replace fiduciary judgment. It does not send client communications, execute trades, move money, or make final recommendations on its own. The advisor decides what reaches the client.
View our live trust center