3
AC
Quality/Compliance

Compliance, Safety & Risk

Configurable policy packs and detections. Controls support implementation — certification depends on audits and org processes, not software alone.

Certification disclaimer

ZiplyHuman includes monitoring and control features aligned to common policy frameworks. Presence of these features does not constitute PCI, HIPAA, SOC 2, or other regulatory certification. Compliance status depends on your implementation, configuration, and independent audits.

Open risk signals

13

Safety score

98.4

Policy packs

11

Monitoring packs

Enable per agent / environment

General privacy

PII handling, minimization, access controls

configurable

Customer & recording consent

Consent collection and recording notices

configurable

PCI DSS aligned

Payment card data detection & redaction controls

configurable

HIPAA-aligned workflows

PHI detection for healthcare agents

configurable

Financial-services policies

Disclosures, advice restrictions

configurable

Healthcare policies

Clinical claim restrictions

configurable

Debt-collection policies

FDCPA-style disclosures and hours

configurable

Insurance policies

Product claim and disclosure packs

configurable

Customer-authentication policies

Identity verification steps

configurable

Age-restricted services

Age gate and restricted content

configurable

Internal company policies

Brand and internal code of conduct

configurable

Risk detections (production)

Detection typePackCount (7d)Severity
Payment-card dataPCI DSS3critical
National identity numbersPrivacy1critical
Passport numbersPrivacy0high
Bank-account dataFinancial2critical
Health informationHIPAA-aligned0critical
Authentication credentialsAuth1critical
PasswordsPrivacy0critical
API keysPrivacy0critical
ProfanityInternal14low
HarassmentInternal1high
DiscriminationInternal0high
ThreatsInternal0critical
Self-harm referencesSafety0critical
Prohibited claimsFinancial2high
Unapproved financial adviceFinancial1high
Unapproved medical adviceHealthcare0high
Missing disclosuresDebt collection12high
Missing consentConsent4high
System-prompt leakageSecurity0critical
Prompt injectionSecurity14medium
Jailbreak attemptSecurity6medium
Data-exfiltration attemptSecurity1critical

Data controls

Configurable per tenant / residency region

RedactionTokenizationMaskingEncryptionRetention policiesData residencyDeletion / right to eraseLegal holdAccess approval