Your data: exports, backups & retention
Your records are yours, and a compliance system that is hard to leave is a compliance risk of its own. This page covers how to get data out of Zovos, what backups exist, how retention, legal holds and deletion work, and who else touches the data. Where a figure is involved we point at our security page, which is the page we keep current.
Who controls what
Under your agreement, your institution is the controller of everything you put in the platform and Zovos is the processor. That means your privacy practices govern that content, and requests about it run through you.
Our privacy policy covers a separate and much smaller set of information. That is what we collect about site visitors, newsletter subscribers, and people who contact us. It does not govern your tenant content.
Inference runs on AWS Bedrock, which does not store prompts or completions or use them to train models, and Zovos does not train on customer data. That commitment, and the boundary the model inference runs inside, are stated on the security page. AI features retrieve only content the requesting member could open themselves, and due-diligence questionnaire answers, which go to counterparties, draw on your policies only.
Getting your data out
There is no export you have to ask us for. Everything below is in the product:
- Register exports. You get server-stamped PDF and XLSX exports for the risk register, gap report, findings, loss events and program inventory. Most tables also offer quick CSV downloads.
- Scheduled exports. Datasets are exported on a timer and kept for you to download from Settings through a short-lived secure link, or dropped on your own SFTP server with a pinned host key. Email is configurable as a destination too, but Zovos does not send email today, so that leg stays inert until delivery is switched on. A schedule cannot widen access. It is the configuring owner's own export, executed on a timer and carrying that owner's permissions.
- Audit-log forwarding. The SIEM forwarder you configure on the Integrations tab of Settings delivers audit events continuously to Splunk, Microsoft Sentinel or a generic collector, so your security operations team holds its own copy.
- Proof packs. These are sealed artifacts that ship with a standalone verifier, so a third party can check integrity without trusting our running system.
- Scoped API tokens. Use these for pulls you script yourself. A token reads only the register its scope names, which is one of risks and assessments, controls, policies, or third parties. It reads page by page, and every row carries a last-updated stamp so a scheduled job can take only what changed. Tokens are stored hashed, and revoked rather than deleted, so the record of what existed survives.
Audit trail and exports and Connecting integrations cover the mechanics.
Backups
Infrastructure runs across multiple availability zones within a single United States region, with continuous backup and point-in-time recovery. The backup retention window is published on the security page.
We are deliberately not publishing recovery-time commitments. A cross-region standby does not exist today and a restore drill has not yet been run, so any recovery-point or recovery-time number would be a design target rather than a measured one. Our launch service level is stated in the Terms, and both positions move once the drill is done.
Retention, legal holds and deletion
Retention is configured per tenant under the Data & retention tab in Settings & integrations. The tab states your region, the evidence and agent-run-log retention in force, how content is encrypted and how keys are managed, and your right-to-erasure posture. That last item states what happens to your data at offboarding. It is not a tool for making requests. Below it sit your retention classes, your legal holds, and the custom fields you have defined on the core registers. The default retention posture is a storage floor rather than a cryptographic lock, and the security page states it in those terms.
A legal hold blocks erasure. A record covered by a hold is not deleted while the hold stands. The gate is enforced, not advisory. That matters when litigation or an examination outlasts a retention class.
Records that reach the end of their retention class do not disappear quietly. They surface in the document library under a Due for disposition filter. There a named person records one of two decisions: retain the record, or clear it for disposal. The decision lands in the audit trail. Neither decision destroys anything. There is no destruction action in the product, and nothing is disposed of automatically. A record under an active legal hold cannot be reviewed at all until the hold is released.
At offboarding, we erase database content by dropping your tenant schema and erase object storage by destroying your tenant key. Both sit behind the same blocking legal-hold gate. The security page publishes the timeline. Take your final export before that window closes, and put it on your exit checklist instead of relying on a last-minute request.
Who else touches your data
A small number of subprocessors touch customer data, and they are named in full on our subprocessors page: hosting, model inference, identity, and the administrative network path. Amazon SES is provisioned for transactional email, but that email is not yet enabled. We disclose operational vendors that support the service without processing customer content as well, because omissions read as concealment in a vendor review. Customers get advance notice before a new subprocessor processes customer data. Request traces carry only the route, timing and status, never record content, and are kept in CloudWatch in our AWS account for 30 days.
Requests from individuals
If a consumer or an employee asks for access to, correction of, or deletion of information held in your Zovos tenant, that request runs through you as the controller. Zovos has no consumer-request intake of its own. What supports your response is what is already in the product: the exports above, the legal-hold controls in settings, and the audit trail's record of what was done.
Requests about information Zovos holds directly, such as site visits, newsletter subscription and correspondence with us, go to privacy@zovos.ai and are answered under our privacy policy, which sets out the access, correction, deletion and portability rights we honor for residents of every US state.
Notes and limits
- Zovos runs in a single region today. If a data-residency requirement outside the United States applies to you, we cannot meet it.
- A restore drill has not been run, and we say so rather than publish a recovery target.
- The data processing addendum we can send is a draft, available under a mutual NDA. There is no executed standard template today, and we would rather tell you that during diligence than during contracting.