3
Incident4 Inc17 WarnUpd 1s
Quality/Compliance

Compliance, Safety & Risk

Configurable policy packs and detections. Controls support implementation — certification depends on audits and org processes, not software alone.

Certification disclaimer

ZiplyHuman includes monitoring and control features aligned to common policy frameworks. Presence of these features does not constitute PCI, HIPAA, SOC 2, or other regulatory certification. Compliance status depends on your implementation, configuration, and independent audits.

Open risk signals

13

Safety score

98.4

Policy packs

11

Monitoring packs

Enable per agent / environment

General privacy

PII handling, minimization, access controls

configurable

Customer & recording consent

Consent collection and recording notices

configurable

PCI DSS aligned

Payment card data detection & redaction controls

configurable

HIPAA-aligned workflows

PHI detection for healthcare agents

configurable

Financial-services policies

Disclosures, advice restrictions

configurable

Healthcare policies

Clinical claim restrictions

configurable

Debt-collection policies

FDCPA-style disclosures and hours

configurable

Insurance policies

Product claim and disclosure packs

configurable

Customer-authentication policies

Identity verification steps

configurable

Age-restricted services

Age gate and restricted content

configurable

Internal company policies

Brand and internal code of conduct

configurable

Risk detections (production)

Detection typePackCount (7d)Severity
Payment-card dataPCI DSS3CriticalCritical
National identity numbersPrivacy1CriticalCritical
Passport numbersPrivacy0highhigh
Bank-account dataFinancial2CriticalCritical
Health informationHIPAA-aligned0CriticalCritical
Authentication credentialsAuth1CriticalCritical
PasswordsPrivacy0CriticalCritical
API keysPrivacy0CriticalCritical
ProfanityInternal14lowlow
HarassmentInternal1highhigh
DiscriminationInternal0highhigh
ThreatsInternal0CriticalCritical
Self-harm referencesSafety0CriticalCritical
Prohibited claimsFinancial2highhigh
Unapproved financial adviceFinancial1highhigh
Unapproved medical adviceHealthcare0highhigh
Missing disclosuresDebt collection12highhigh
Missing consentConsent4highhigh
System-prompt leakageSecurity0CriticalCritical
Prompt injectionSecurity14mediummedium
Jailbreak attemptSecurity6mediummedium
Data-exfiltration attemptSecurity1CriticalCritical

Data controls

Configurable per tenant / residency region

RedactionTokenizationMaskingEncryptionRetention policiesData residencyDeletion / right to eraseLegal holdAccess approval