Platform · Audit and security

Say yes faster. Prove every decision.

Speed for the business and diligence for the regulator, held together: the record writes itself as the work happens, so a case from 14 months ago exports in minutes, not a week of screenshots.

30 minutes. Your data. No slides.
The audit trail in Compliance Hub: write-once event log with evidence-pack export
Trail
Written once, never changed
32 event types · exported in one click
A UK wealth manager A private bank A fund administrator A global auction house names on request
Why they chose it
“When the regulator asked about a decision from over a year ago, we used to lose a week to screenshots and email threads. Now the whole case exports as one evidence pack in minutes, and every action, override and sign-off is already there. The record builds itself while we work.”

Head of financial crime · UK wealth manager · 11 years in role

What you get today

Audit native, so the record writes itself.

The “safely” that runs under every stage of the funnel, made provable. Every decision, override and action is written once, timestamped, and never changed. Shipped today, no AI required.

Event trail: status changes, overrides and actions as they happen
Record · nothing to reconstruct later

Record everything, automatically

Every decision, status change, override, escalation and automated action is written to the trail as it happens, so there is nothing to reconstruct later. 32 immutable event types across 8 categories, with millisecond timestamps and correlation IDs on every entry.

See the trail
Four-eyes: maker performs, named checker approves
Manage · both names on the high-risk call

Put both names on the high-risk call

Four-eyes is enforced where you require it: the maker performs the action, a separate checker approves it, and both are attributed to named users in the same write-once trail. Mapped to the FCA Senior Managers Regime, and configurable in Studio without an engineering ticket.

Configure in Studio
Evidence pack: chain assembled, mapped to SAR documentation
Export · review and file, do not rebuild

Stop assembling the SAR by hand

Because every action is already in the trail, the evidence chain builds itself as the investigation runs, and exports as a single evidence pack mapped to SAR documentation. Your analyst reviews and files rather than reconstructs, with four-eyes sign-off included.

See an export
Data residency: EU, US and APAC, AES-256 at rest
Residency · infrastructure your risk team trusts

Choose where your data lives

Keep customer and compliance data in the EU, US or APAC, with EU and Finland hosting available. Data is AES-256 encrypted, and in many deployments Zenoo orchestrates the checks without retaining the underlying data. ICO registration, a signed DPA, and 5-year retention where required.

Talk to security
One honest note

Zenoo's own ISO 27001 is on our roadmap, not held today. The certified infrastructure your data runs on is a separate matter from our own programme, and we will always tell you which is which. If security assurance is a procurement requirement, we share the full infrastructure detail in the security discussion.

32
immutable event types across 8 categories
1 click
evidence-pack export mapped to SAR docs
AES-256
encryption at rest, EU, US and APAC
40 min
regulator export (platform benchmark)
Zenoo Labs · alpha with design partners

The first-draft SAR narrative, written from the evidence chain.

In alpha with design partners, the Case Narrator, one of the 10 specialised agents, drafts a first-draft SAR narrative from the assembled evidence chain with sources cited inline, for the analyst to check, edit and file. Opt-in, human-in-the-loop, and never autonomous.

AI drafts. A human always decides and files.

Labs: the Case Narrator drafting a SAR narrative with inline sources
Proof

A UK wealth manager runs a major Zenoo deployment, hardened through independent penetration testing and successive enhancement cycles.

We do not publish our customers' names. Named references and full case studies are shared privately, on request, once the client approves. The same discretion we would give you.

Questions

Audit and security, honestly.

What exactly is written to the audit trail?

Every event that changes a case: status transitions, risk overrides, escalations, approvals, rejections, automated checks, four-eyes sign-offs, and data-provider responses. 32 event types across 8 categories, each with a millisecond timestamp, user attribution, and a correlation ID linking it to the triggering action. The record is written once and cannot be altered.

How long does a regulator export actually take?

The design target is under 40 minutes for a complete evidence pack on a case, including the full event trail, associated documents, and four-eyes sign-off attribution. That is a platform benchmark based on the way the export is built; your actual time depends on case complexity and the number of attached documents. The point is that you assemble nothing by hand.

What does four-eyes enforcement mean in practice?

You configure which actions require a second named approver in Studio, without an engineering ticket. When an analyst performs a qualifying action, the platform holds it in a pending state until a separate checker approves it. Both the maker and the checker are named in the write-once trail, which is the record a regulator sees.

Where is my compliance data stored?

You choose: EU (including Finland), US, or APAC. In many deployments Zenoo orchestrates the checks without retaining the underlying customer data itself; the data passes through to your chosen providers and the trail records what happened. ICO registration, a signed DPA, and configurable retention periods are included.

Does Zenoo hold any security certifications?

We are working towards ISO 27001 and will say so plainly: it is not held today. The infrastructure your data runs on carries its own certifications, which we share in the security discussion. We will always tell you which is which, and we will not claim a certification we do not hold.

Can we keep our existing data providers and still get the audit trail?

Yes. The audit trail is built into the orchestration layer, not into any individual provider. Whatever checks you run through Zenoo (across any of the 240+ connectors in the marketplace or your own bespoke integrations) the events are written to the same trail and appear in the same evidence export.

Faster yes. Provable decisions. Nothing to reconstruct.

Bring a real case and we will export the whole evidence pack live. If it does not hold up on your data, do not buy it.

30 minutes. Your data. No slides.