Early accessZiel Revenue OS is open for design partners — deep 25-min product interview
Ziel LabRevenue OS
Security

Enterprise-grade isolation. On day one.

Every workspace has its own encryption key, its own row-level security policies, its own audit trail. Third-party tokens are envelope-encrypted with a key derived from your workspace ID. Nobody at Ziel Lab can read them.

Isolation

Every workspace is a tenant. Every tenant is on its own.

Data isolation is enforced at the database layer via row-level security policies on every table — not just checked in application code. A per-workspace encryption key derived via HKDF from a master root key means secrets stored in one workspace cannot be decrypted using another workspace's context. There is no shared token store, no shared context leaking across tenants.

Data flow · BYOK

Choose where your AI data flows.

On the default tier, LLM calls go through Ziel Lab's infrastructure. On BYOK, you connect your own Anthropic, OpenAI, or OpenRouter account — LLM data flows directly through your provider account and never touches ours. This is the model your procurement and compliance teams will actually approve. Same €899/mo either way.

Audit

Every AI call, every system write, logged with reason.

Ziel writes an audit-log row for every LLM call (model, tokens, cost, feature), every secret read, every CRM property write, every skill invocation, and every accepted proposal. The audit log is queryable per workspace and never truncated. Nothing Ziel does to your CRM is unaccountable.

Permissions

Ziel respects your existing CRM roles.

When Ziel reads from HubSpot or writes to a Gmail draft, it does so under the OAuth grant of the connecting user — inheriting exactly the permissions that user has in the source system. A rep who cannot see Enterprise deals in HubSpot cannot see them through Ziel either. No permission escalation, no service-account backdoor.

Trust points

The specifics your security team asks for.

Hosting

EU-hosted infrastructure (Railway EU region + Supabase EU). US and other regions available on FDE tier.

Encryption in transit

TLS 1.3 for every connection — customer, vendor, model provider.

Encryption at rest

AES-256 for the entire Postgres volume. AES-256-GCM envelope encryption for tenant secrets on top.

Session isolation

Magic-link authentication via Supabase Auth. Session cookies HttpOnly, Secure, SameSite=Lax.

Backups

Point-in-time recovery on Postgres. Nightly encrypted snapshots.

Data residency (BYOK)

When you BYOK, LLM data flows through your provider account. Nothing to residency-review on our side.

Compliance posture

GDPR-first from day one. SOC 2 Type II in flight (target Q1 2027).

Data export

Every workspace can export its full state to CSV/JSON. No lock-in.

What Ziel Lab does not do

Security review with your team? We're ready.

Book a call — we'll walk your security lead through the architecture and answer their questions.

Join as a design partner →