Compliance, Safety & Risk
Configurable policy packs and detections. Controls support implementation — certification depends on audits and org processes, not software alone.
Certification disclaimer
ZiplyHuman includes monitoring and control features aligned to common policy frameworks. Presence of these features does not constitute PCI, HIPAA, SOC 2, or other regulatory certification. Compliance status depends on your implementation, configuration, and independent audits.
Open risk signals
13
Safety score
98.4
Policy packs
11
Monitoring packs
Enable per agent / environment
General privacy
PII handling, minimization, access controls
configurableCustomer & recording consent
Consent collection and recording notices
configurablePCI DSS aligned
Payment card data detection & redaction controls
configurableHIPAA-aligned workflows
PHI detection for healthcare agents
configurableFinancial-services policies
Disclosures, advice restrictions
configurableHealthcare policies
Clinical claim restrictions
configurableDebt-collection policies
FDCPA-style disclosures and hours
configurableInsurance policies
Product claim and disclosure packs
configurableCustomer-authentication policies
Identity verification steps
configurableAge-restricted services
Age gate and restricted content
configurableInternal company policies
Brand and internal code of conduct
configurableRisk detections (production)
| Detection type | Pack | Count (7d) | Severity |
|---|---|---|---|
| Payment-card data | PCI DSS | 3 | critical |
| National identity numbers | Privacy | 1 | critical |
| Passport numbers | Privacy | 0 | high |
| Bank-account data | Financial | 2 | critical |
| Health information | HIPAA-aligned | 0 | critical |
| Authentication credentials | Auth | 1 | critical |
| Passwords | Privacy | 0 | critical |
| API keys | Privacy | 0 | critical |
| Profanity | Internal | 14 | low |
| Harassment | Internal | 1 | high |
| Discrimination | Internal | 0 | high |
| Threats | Internal | 0 | critical |
| Self-harm references | Safety | 0 | critical |
| Prohibited claims | Financial | 2 | high |
| Unapproved financial advice | Financial | 1 | high |
| Unapproved medical advice | Healthcare | 0 | high |
| Missing disclosures | Debt collection | 12 | high |
| Missing consent | Consent | 4 | high |
| System-prompt leakage | Security | 0 | critical |
| Prompt injection | Security | 14 | medium |
| Jailbreak attempt | Security | 6 | medium |
| Data-exfiltration attempt | Security | 1 | critical |
Data controls
Configurable per tenant / residency region