Trust & security
Trust should be inspectable, scoped and revocable.
This page describes controls implemented in the current product. It does not claim universal compliance, transaction legality or counterparty performance.
Implemented controls
What the platform enforces today.
Database-derived access
Roles and capabilities come from authenticated organization membership and deal assignments. The browser cannot switch role or grant itself access.
Encrypted evidence vault
Private evidence uses per-file envelope encryption, explicit grants, malware scanning, retention dates and an audited download path.
Human verification
Automation may extract and compare. An authorized human reviewer makes the final case decision and every attestation states its limitations.
Immutable execution plan
Required parties approve a hashed snapshot of participants, fees, reveal rules and exact locked document versions.
Atomic release
Approved identity fields, documents and signatures move together in one serializable database transaction or none of them move.
Verifiable close
The encrypted closing package references the frozen documents, signatures, attestations, consent and audit-chain material without raw evidence.
What Zeklio does not guarantee
An attestation is a narrow transaction-bound statement, not a guarantee that a person will perform, an asset exists, funds are clean, title is valid or a transaction is lawful in every jurisdiction.
Legal wording, verifier scope, sanctions/KYB provider, data-controller roles, retention and permitted pilot jurisdictions require professional approval before external production use.
Operational transparency
Security questions should have a direct answer.
For pilot due diligence, request the current data-flow diagram, subprocessor register, retention schedule, recovery evidence and incident contact through the demo form.