// privacy-first architecture

Your data never leaves your network.

ZDZCloud is built for those who can't outsource trust — regulated industries, security teams, sensitive data. Run on-premise, with local AI and LGPD by design. Here's how.

🏢

On-premise, no lock-in

Run 100% on your own infrastructure — cloud or fully local. You own the code and the data; nothing is locked to a vendor.

where: ZDZAgentsOS (cloud or 100% local) · on-premises DevSecOps foundation
🔒

Local AI, private inference

When a product uses an LLM, it can run locally (Ollama) — inference is isolated per client and your data never goes to a third-party cloud.

where: ZDZAIShield (100% local NLP classification) · ZC Investimentos
🛡️

Data doesn't leak to public AI

ZDZAIShield inspects every prompt and blocks (HTTP 403) tax IDs (CPF/CNPJ), card numbers, passwords, and keys from being sent to the monitored public AI services.

monitors 7 destinations (ChatGPT, Gemini, Claude, Copilot, DeepSeek, Perplexity, HuggingFace)
📋

LGPD by design

Encrypted PII (AES-256), data minimization, legal basis, mandatory e-mail verification, and a leaked-password blocklist — built into the foundation, not patched on later.

where: our house engineering standard (e.g. Pet Planner)
🧾

Human in the loop + auditing

Every action that matters is approved by a person (Action Inbox) and gets recorded. Timeouts guarantee the flow never stalls — and nothing happens without a trail.

where: ZDZAgentsOS · the method
🌐

DataVerse: public-only, aggregate-only

We work with official public data, with field-by-field provenance (197 million records). We never expose an individual person's record.

where: ZDZDataVerse · LGPD legal basis for public data

Privacy isn't a setting. It's the architecture.

The in-house infrastructure (on-premises mini-datacenter, SIEM, SSO, observability) that runs our products is the very same one that lets you keep your data at home.

For CISOs & DPOs

Where does my data live?
On your infrastructure, when you choose on-premise/self-hosted. No vendor lock-in — you keep control of the data and the code.
Does the AI send my data outside?
When the product uses a local LLM (Ollama), no — inference is private and isolated per client. And ZDZAIShield exists precisely to block sensitive data from reaching public AIs, with HTTP 403.
How does this comply with the LGPD?
By design: minimization, PII encryption (AES-256), legal basis, and provenance. In DataVerse, only aggregated public data — never the exposure of an individual record.
How do I know what the AI did?
End-to-end auditing: every AI decision and every human approval is recorded, with timeout and rollback. You get the complete trail.
This page describes the privacy architecture of our products. Specific requirements (certifications, DPA, dedicated hosting, penetration testing) are handled case by case — talk to the technical team.

Have a specific security requirement?

Talk to our technical team — we design the hosting and isolation for your case.

Talk to the technical team →