ZecoCM
Trust

Security & Trust

Last updated: August 26, 2026

This page describes the architectural controls ZecoCM's project-record and TRACE AI systems are actually built with today, and is deliberately plain about what is not yet true — including formal third-party certification. If you are evaluating ZecoCM for a public-agency or enterprise procurement and need something this page doesn't answer, contact us directly.

Where we are today: ZecoCM is an early-stage company. We have not completed a SOC 2 audit, FedRAMP authorization, or an independent penetration test. The controls below are real and enforced in the application today, but they have not yet been verified by an outside auditor. Treat any claim on this page as "built this way," not "certified this way," until we say otherwise.
Tenant isolation The append-only evidence model Authorization-scoped AI (TRACE) Access control and authentication Encryption and infrastructure Data export and portability Retention and deletion Subprocessors Reporting a security issue

Tenant isolation

Every request that reaches project data is scoped to a tenant. Customer-side users always carry their own tenant context and cannot see another organization's projects, documents, or records. Platform staff accounts carry no tenant context by default; a staff member can only see a specific customer's data by deliberately switching into a browse-tenant context for that customer, and that action is not silent — it changes what the account can see for the duration of the session, not a standing permission.

The append-only evidence model

Governed determinations — certifications, change-order approvals, contract-clock calculations, TRACE citations and refusals — are never silently edited in place. A correction supersedes the prior state and is recorded alongside it, not over it. This is the same property the homepage describes as "the present never rewrites the past," and it applies to the underlying data model, not just the marketing copy.

Authorization-scoped AI (TRACE)

TRACE, ZecoCM's governed assistant, only retrieves documents and records the requesting user is already authorized to see under the tenant-isolation rules above — it never infers access from a higher-privileged grant elsewhere in the system. A substantive TRACE answer requires a citation to project evidence; when the evidence is insufficient, contradictory, or unreliable, TRACE is designed to escalate or refuse rather than guess. Content extracted from customer documents (including OCR'd text from scanned drawings) is treated as untrusted data, not as instructions to the AI — a drawing or PDF cannot direct TRACE to take an action or change its own behavior.

Access control and authentication

Application access is authenticated per user, with role-based permissions that separate ordinary project users from platform administrators. We do not ask users to share credentials, and we do not store payment card data ourselves — payment processing, where applicable, is handled by a third-party processor.

Encryption and infrastructure

Traffic between your browser and ZecoCM is encrypted in transit (HTTPS/TLS). ZecoCM's production infrastructure is currently a single-region deployment operated by a small engineering team rather than a large multi-region hosting footprint. We are direct about this because it is a real characteristic of an early-stage product, and because it should factor into your own risk assessment — it is not something we ask you to take on faith.

Data export and portability

ZecoCM is built so that leaving the platform does not mean losing your evidentiary record: the export path is designed to produce your project's record, provenance, hashes, and verification information in a portable package that can be checked without continued access to the ZecoCM application. We do not consider your project history something we should be able to hold hostage.

Retention and deletion

Project records are retained for the duration of your organization's agreement with ZecoCM and for any additional period required by the public-records or contract-retention rules applicable to your project. See our Privacy Policy for how this applies to personal information specifically.

Subprocessors

ZecoCM relies on a small number of infrastructure and AI-model subprocessors to operate the Service (for example, cloud hosting and the AI model provider behind TRACE). A current list is available on request at hello@zecocm.com.

Reporting a security issue

If you believe you've found a security vulnerability in ZecoCM, please report it to security@zecocm.com before disclosing it publicly. We will acknowledge reports and work with you in good faith to understand and address the issue.

This page is a plain description of current architecture, not a security certification, a warranty, or a substitute for your own organization's security or procurement review. Nothing here overrides the terms of a signed agreement between your organization and Zeco Inc.