TRUST AT ZUBU

Security

Security information, shared responsibilities and reporting concerns.

Draft for client review · 5 September 2026

Report a security incident

Data control in legal workflows

Zubu supports legal hold, preservation and enterprise collection workflows across connected business platforms. Its service model includes preserving information in place and collecting to customer-controlled destinations where configured.

A customer-controlled destination and an in-place workflow do not eliminate the need to secure accounts, integrations, operational metadata and source systems. The responsibilities for each component should be documented in the services agreement.

Customer-managed access and integrations

Customers determine who may administer their organization and which source systems and data are authorized for a workflow. Review permissions, protect integration credentials and remove unnecessary access promptly.

Use the identity and authentication controls available for your configuration, restrict administrator privileges and review account activity. Permissions or source-system retention changes can affect preservation and collection results.

Preservation, collection and audit evidence

Customers and their legal advisers determine the scope and duration of legal holds. Verify workflow outcomes, review failures and keep the records required for your legal and operational needs.

Before deleting information, disabling a connector or ending service, assess ongoing holds and retention obligations. Audit records support review, but customers must confirm their required coverage, export capability and retention with Zubu.

Customer-controlled storage

For collection to a customer-managed storage destination, the customer configures destination access and lifecycle policies and manages the applicable storage service. Review permissions, encryption configuration, backup needs and deletion rules for that environment.

Source-provider behavior, available APIs, licensing and configuration can affect the workflow. Agree the supported integration and data-handling arrangements before relying on a production collection.

Security documentation and assurance

For a security review, contact Zubu to discuss the applicable architecture, data flows, hosting locations, access controls, encryption, incident response and service-provider documentation. Availability of particular evidence should be confirmed with the team.

Any security schedule, data processing agreement or service-level commitment applies according to its agreed scope. This page does not claim an issued SOC 2 report, ISO certification, a specific encryption standard, fixed recovery targets or a particular testing cadence.

Report a security concern

Send an initial report to security@zubu.ai with the subject “Security report”. Include the affected product or URL, a concise description, approximate time and a safe way to contact you. Request a suitable secure channel before sharing sensitive evidence.

Do not include passwords, secret keys or customer case data in ordinary email. Avoid accessing another organization’s information, disrupting service or conducting intrusive tests without prior written authorization. This contact method is not a grant of testing permission or a bug-bounty commitment.

Incident coordination and customer notices

For a suspected account compromise, follow your organization’s incident process and contact Zubu promptly. Coordinate any credential or integration changes so that necessary containment also considers ongoing preservation obligations.

Notification deadlines, investigation assistance and remediation duties are determined by the applicable agreement and law. Contact details and customer escalation responsibilities should be kept current.

Questions about security or privacy

Email security@zubu.ai for security concerns, incident reports and questions about the service’s security responsibilities. For personal-information handling and privacy requests, consult the Privacy Policy. General inquiries can be sent to contact@zubu.ai.

Privacy Policy · Security · Terms of Service