Confidentiality is the product. Here's exactly how we protect your data.
Data & security

Built so you can hand us your portfolio.

We ask a sponsor to trust us with their most sensitive financial detail — who owes them, how much, and for how long. Everything below exists so that's an easy yes.

The commitments

Six promises we design around.

Isolation by defaultYour accounts live in your own space. They are never pooled with another client's or used to train a shared model.
Closed AI systemAn owned, enclosed recovery model is in build. Your files stay inside the perimeter — nothing is sent to a public model.
Data minimizationWe work from six billing-level fields per invoice. No data-room, no systems access, no more of your data than the job requires.
Client-approved outreachNothing reaches your customer in your name that you haven't cleared. You approve every message before it's sent.
Funds never touch usDebtors pay you directly. We don't hold your money — which removes an entire category of risk.
Attorney privilege & supervisionThe engagement runs under a licensed attorney — with the confidentiality obligations that come with the profession.
The AI, honestly

The model learns from our doctrine — not from your data.

The system that triages and drafts is guided by a 65,000-file recovery playbook that is ours, built over 30 years and scrubbed of client identifiers. It gets sharper by refining that doctrine — never by absorbing one client's accounts into another's. Your data is used only to work your files, then it stays put.

A licensed attorney supervises the model as a non-lawyer assistant would be supervised. It drafts and prioritizes; judgment, and anything client-facing, stays with a lawyer. Execution scales. Discretion doesn't get outsourced.

What trains the model vs. what doesn't
Zindo's own 65,000-file doctrineAnonymized patterns of what gets recovered, and how.
Attorney playbook & rulesCodified judgment from three decades of files.
Your client accountsUsed to work your files only. Never pooled, never shared.
Any public / third-party modelYour data never leaves the closed system.
Where we are

An honest security posture.

We'd rather tell you what's in place and what's in progress than claim a badge we haven't earned yet.

In place

Per-client data isolation, data minimization to six fields, client-approved correspondence, encryption in transit, attorney supervision, and direct-to-client remittance.

Being finalized

SOC 2 Type II examination is underway with a third-party assessor. Encryption at rest and cyber/E&O coverage are in final steps.

On request, under NDA

Our data-handling summary, security questionnaire responses, and references — shared privately at diligence, never broadcast.

Questions security teams ask

The details.

No. Your accounts are used only to work your files. The model improves by refining our own anonymized 65,000-file doctrine — not by absorbing your data. There is no cross-client training and no leakage path between accounts.

Six billing-level fields per invoice are enough to identify what's recoverable. No data-room, no ERP access, no customer PII beyond what's already on the invoice. Less data is less risk — for both of us.

A SOC 2 Type II examination is underway with a third-party assessor. We won't claim the attestation before it's issued. We're glad to walk your security team through our current controls and timeline under NDA.

Directly to you. Debtors remit to the creditor, not to us. We're paid a success fee afterward — which means your funds never sit in our account and never depend on our solvency.

Access is limited to the people working your files, under attorney supervision and professional confidentiality obligations. Our whole business rests on discretion — the same reason we'll never name you publicly.

Hand us the files you'd never risk with anyone else.

That's the point. If we treat your worst, most sensitive accounts right, you already know how we'll treat the rest.