Frequently Asked Questions¶
Common questions about Zotniq.
General¶
What is Zotniq?¶
Zotniq is a Data Loss Prevention (DLP) solution designed for AI applications. It detects and prevents sensitive data from being sent to AI tools, vendors, or customers.
How is Zotniq different from traditional DLP?¶
| Traditional DLP | Zotniq |
|---|---|
| Network-level | Application-level |
| Email/file focused | AI/API focused |
| Heavy agents | Lightweight SDK |
| Complex rules | Simple policies |
| Days to deploy | Minutes to deploy |
What data types does Zotniq detect?¶
- PII: SSN, email, phone, address, names
- PHI: Medical records, health IDs
- Financial: Credit cards, bank accounts, tax IDs
- Secrets: API keys, passwords, tokens
- Custom: Define your own patterns
Security¶
Does Zotniq see my data?¶
No. Content is processed locally by the SDK. Only metadata (timestamps, decisions, detection types) is sent to the cloud in default mode.
For maximum privacy, use METADATA retention mode - no content is ever stored.
How is my license key protected?¶
- License keys are validated against signed JWT tokens
- JWTs use RS256 asymmetric encryption
- Keys can be rotated instantly from the dashboard
- Revocation is immediate and cascades to all policies
Where does Zotniq stand on SOC 2?¶
Zotniq is built to support SOC 2 audit requirements: data classification, role-based access control, immutable audit logging, and encrypted-at-rest retention. Formal Type II attestation is in progress — contact sales for our current compliance posture and expected audit timeline.
Integration¶
Which languages are supported?¶
Currently:
- Python — Full SDK with the OpenAI drop-in wrapper.
For other languages, call the REST API directly:
curl -X POST https://api.zotniq.ai/v1/preflight/text \
-H "X-Zotniq-API-Key: zot_sk_..." \
-H "Content-Type: application/json" \
-d '{"text": "...", "destination": "AI_TOOL"}'
Other-language SDKs may follow depending on customer demand; nothing is committed on the roadmap today.
Does Zotniq work with LangChain?¶
Yes! Native LangChain integration:
# v0.2: from zotniq.integrations.langchain import ZotniqCallbackHandler
handler = # v0.2: ZotniqCallbackHandler(license_key="...")
llm = ChatOpenAI(callbacks=[handler])
Does Zotniq work with OpenAI?¶
Yes! Protected OpenAI client:
from zotniq.integrations.openai import wrap_openai
client = SafeOpenAI(
api_key="sk-xxx",
api_key="zot_lic_xxx"
)
Can I use Zotniq without a license key?¶
Yes, in offline mode for testing:
This uses default patterns without cloud policy sync.
Performance¶
What's the latency overhead?¶
- Local mode (
mode="local"or noapi_key): a few milliseconds per call — pure regex + Luhn/IBAN/SSN validators + PHI keyword scan, no network. - Cloud mode (
mode="cloud"withapi_key): local latency plus one HTTPS round-trip toapi.zotniq.ai/v1/preflight/textfor the LLM contextual pass.
Concrete numbers depend on payload size and network path — measure in
your environment with zotniq check --mode local <text> vs
zotniq check --mode cloud <text> to see the actual overhead.
Does Zotniq slow down my AI calls?¶
Local mode is negligible (regex-only, single-digit ms). Cloud mode
adds one round-trip; if you can't afford it on the hot path, set
mode="local" on the calls that matter and reserve cloud for
audit-triggered or higher-risk payloads.
Can I use Zotniq in production?¶
Absolutely. Zotniq is designed for production use with:
- Automatic retries and fallbacks
- Connection pooling
- Graceful degradation
- No blocking on cloud failures
Policies¶
How do I create a policy?¶
- Dashboard: Organization → Policies → Create Policy
- API:
POST /api/orgs/{org_id}/policies - SDK: Policies sync automatically from cloud
Can different departments have different rules?¶
Yes! Use Policy Groups:
client = Zotniq(api_key="...")
engineering = client.with_policy_group("engineering")
marketing = client.with_policy_group("marketing")
What actions can policies take?¶
| Action | Behavior |
|---|---|
| BLOCK | Prevent content from being sent |
| MASK | Redact sensitive data, allow rest |
| ALLOW | Permit content (for audit only) |
Compliance¶
Is Zotniq GDPR compliant?¶
Yes. Zotniq helps with GDPR compliance:
- Data residency options (EU, US, APAC)
- METADATA mode (no content storage)
- Audit logging for accountability
- Pseudonymization via masking
How does Zotniq help with HIPAA?¶
Zotniq gives you technical controls that map to HIPAA safeguards:
- PHI detection and blocking on outbound flows
- Audit trails of every decision
retention_mode=METADATAfor the no-content-storage posture
A Business Associate Agreement is not standard today — contact sales if HIPAA coverage under a BAA is a deal requirement and we'll scope what's possible.
How does Zotniq help with SOC 2?¶
Zotniq provides technical controls that map to common SOC 2 evidence requirements:
- Access controls (RBAC, per-team API keys, admin impersonation audit)
- Audit logging (every preflight decision, append-only)
- Data protection (masking, retention modes, in-transit + at-rest encryption)
- Monitoring and alerting (SIEM forwarding to your existing SOC pipeline)
Pricing¶
Current published tiers, limits, and add-ons live at zotniq.ai/pricing — the source of truth. The Trial plan is free and doesn't require a card.
Enterprise deals are scoped case-by-case: volume, deployment topology, compliance packs, and support model depend on what you need. Contact sales to talk through requirements.
Troubleshooting¶
"License validation failed"¶
Causes: 1. Invalid license key 2. Expired license 3. Network connectivity issue
Solutions:
# Check license status
zotniq --check-latest
# Validate manually
curl -H "Authorization: Bearer zot_lic_xxx" \
https://api.zotniq.ai/v1/license/validate
"No detections found"¶
Causes: 1. Data format doesn't match patterns 2. Policy rules are disabled 3. Wrong destination specified
Solutions:
# Test with offline mode
client = Zotniq() # no key = local-only
result = client.preflight.check("SSN: 123-45-6789", "AI_TOOL")
print(result.detected) # Should show SSN
"SDK import error"¶
Solutions:
# Reinstall SDK
pip install --upgrade zotniq
# Check Python version (3.9+ required)
python --version
Support¶
How do I get help?¶
- Documentation: You're here!
- Email: support@zotniq.ai
Enterprise customers can request a shared support channel as part of deal scoping — contact sales.
See Also¶
- Getting Started - Quick start guide
- SDK Reference - Full documentation