Zeklio

Security

Product data and marketing data stay separate.

Zeklio App and zeklio.com use different databases, storage, cookies, secrets and runtime networks.

Database-derived access

Roles and capabilities come from authenticated organization membership and deal assignments. The browser cannot switch role or grant itself access.

Encrypted evidence vault

Private evidence uses per-file envelope encryption, explicit grants, malware scanning, retention dates and an audited download path.

Human verification

Automation may extract and compare. An authorized human reviewer makes the final case decision and every attestation states its limitations.

Immutable execution plan

Required parties approve a hashed snapshot of participants, fees, reveal rules and exact locked document versions.

Atomic release

Approved identity fields, documents and signatures move together in one serializable database transaction or none of them move.

Verifiable close

The encrypted closing package references the frozen documents, signatures, attestations, consent and audit-chain material without raw evidence.

Responsible disclosure

Do not include vulnerability details in the demo form. The production security contact and encryption channel must be approved and published before the external pilot.

TLS/CDN/WAF, managed KMS, production alert routing, provider credentials and an isolated restore exercise remain deployment gates. Local implementation is not evidence that these external controls are live.