Security
How ZUUZ protects customer data.
How we process your data
ZUUZ reads the sales conversations in the mailboxes you connect, within the mailboxes and folders you put in scope. We do not browse the rest of your messages, and personal, HR, legal and finance threads are filtered out before processing.
We store the email content ZUUZ processes, encrypted, and delete it when the retention period ends. The default retention period is 60 days, and accounts can choose a shorter email content window, for example 30 days. When it ends, the email text, attachments, meeting transcripts and short AI summaries are deleted from every system ZUUZ runs. Encrypted backups expire within 30 days. The shorter-window option takes effect on a date ZUUZ will confirm.
Metadata (who emailed whom, when, and which emails share a thread) and CRM records stay for as long as you use ZUUZ and contain no email text. If ZUUZ needs an older email after the window, it reads it from your mailbox at that moment and does not store it. Deletion requests are fulfilled within 45 days, and when you leave we delete everything within 45 days of your request.
Encryption
Data is encrypted in transit using TLS, and encrypted at rest. This applies both to content moving between your mailbox provider and ZUUZ, and to email content held during the retention period.
Access controls
Access to customer data is restricted to authorized personnel on a least-privilege, need-to-know basis. Every access is logged and monitored.
Employees and contractors do not read customer message content by default. Access happens only where necessary to comply with a legal obligation, to investigate a security incident, or with your explicit consent for a support request, and any such access is logged, so it can be accounted for after the fact.
Compliance
- SOC 2 Type I: Complete.
- SOC 2 Type II: In progress.
- A Data Processing Agreement (DPA) is available for enterprise customers.
- ZUUZ's access to and use of connected mailbox data (e.g. Google Workspace) complies with the Google API Services User Data Policy, including its Limited Use requirements.
AI and model usage
ZUUZ operates its primary AI models as self-hosted, isolated deployments inside our own infrastructure. Customer data processed by these models is never transmitted to third-party AI providers for training.
Your data is never used to train any general-purpose or foundational AI model. Not ours, and not anyone else's.
Intellectual property and architecture
ZUUZ's core CRM-write technology is covered by three filed U.S. non-provisional patents: autonomous email-to-CRM write, retroactive pipeline discovery, and multi-modal voice and email capture.
These reflect a deterministic-first, LLM-last processing architecture. Rules and structure do as much of the work as they can, and the language model is called last and narrowly, rather than being handed your raw data and trusted to behave.
Contact
For security questions, a copy of our DPA, or our security whitepaper, contact info@zuuz.ai.