Frameworks · Early access
One engine for every framework you answer to.
Each framework becomes a set of checkable rules, with evidence your auditor verifies themselves. Prove a control once, and it counts everywhere it applies.
SOC 2
37 controls · Common Criteria and Privacy
SOC 2 is an attestation report, issued by an independent CPA firm, on how a service organization protects customer data. It’s built on the AICPA’s Trust Services Criteria: security, plus optional availability, confidentiality, processing integrity and privacy.
Explore SOC 2 →HIPAA
45 controls · Security, Privacy and Breach Notification Rules
HIPAA is the US federal law that governs how protected health information (PHI) is safeguarded, used and disclosed. Its Security, Privacy and Breach Notification Rules apply to healthcare providers, health plans and clearinghouses — and to the business associates that handle PHI for them.
Explore HIPAA →ISO 27001
85 controls · ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for an information security management system (ISMS) — the policies, processes and controls an organization uses to manage security risk. The 2022 edition includes a reference set of controls grouped into four themes.
Explore ISO 27001 →BSA / AML
OFAC · BSA · KYC · Reg E, plus fraud checks
The Bank Secrecy Act and anti-money-laundering rules require financial institutions to detect and report financial crime: screening against OFAC sanctions lists, verifying customers (KYC), and filing currency transaction and suspicious activity reports. Reg E adds consumer protections for electronic transfers.
Explore BSA / AML →One control, many frameworks
Prove it once. Count it everywhere.
Frameworks overlap. An access-control check can satisfy SOC 2, HIPAA and ISO 27001 at the same time. ZTZK maps each control across frameworks, so adding one builds on the evidence you’ve already proven instead of starting over.
Using AI in your product?
The same engine enforces your AI policy on every call and proves what it said — model risk, ISO/IEC 42001 and runtime rules.
See AI governance →Request access
Tell us which framework comes first.
We're onboarding a small number of early teams. Pick the framework you need to prove first and we'll show you the evidence.
We use your email only to reply to your request. Privacy policy
✓ Request received. We'll be in touch.