Security
Product data and marketing data stay separate.
Zeklio App and zeklio.com use different databases, storage, cookies, secrets and runtime networks.
Database-derived access
Roles and capabilities come from authenticated organization membership and deal assignments. The browser cannot switch role or grant itself access.
Encrypted evidence vault
Private evidence uses per-file envelope encryption, explicit grants, malware scanning, retention dates and an audited download path.
Human verification
Automation may extract and compare. An authorized human reviewer makes the final case decision and every attestation states its limitations.
Immutable execution plan
Required parties approve a hashed snapshot of participants, fees, reveal rules and exact locked document versions.
Atomic release
Approved identity fields, documents and signatures move together in one serializable database transaction or none of them move.
Verifiable close
The encrypted closing package references the frozen documents, signatures, attestations, consent and audit-chain material without raw evidence.
Responsible disclosure
Do not include vulnerability details in the demo form. The production security contact and encryption channel must be approved and published before the external pilot.
TLS/CDN/WAF, managed KMS, production alert routing, provider credentials and an isolated restore exercise remain deployment gates. Local implementation is not evidence that these external controls are live.