MyZeusCompliance
Trust center · version 3.101

Draft faster.
Keep human authority.

MyZeusCompliance generates structured draft protocols and quality documents through WebChat and Telegram Chat. AI assists authorship and evidence organization; authorized professionals remain responsible for verification, execution, approval, release decisions, and record control.

Current sensitive-data boundary: Do not submit PHI, patient-identifiable data, credentials, regulated originals, or confidential material your organization has not authorized for external processing.

Privacy and data handling

Observed production data flow

Public dashboardThe public shell can store theme, route, session identifiers, and limited chat/news interface state in browser local storage. The visitor counter stores an aggregate count; the public shell does not set a session cookie.
AuthenticationProtected WebChat, Telegram history, upload, document, and operational APIs require a server session. The session token is issued as an HttpOnly, SameSite=Strict cookie and is marked Secure when the reverse proxy reports HTTPS.
WebChatThe request text, session identifier, selected profile, and extracted content from attached PDF or DOCX files are sent through the configured self-hosted Hermes OpenAI-compatible gateway. Hermes can route the request to specialist profiles and its configured model provider. The dashboard repository cannot prove that upstream provider’s retention or training policy; the deployment owner must verify the active Hermes provider configuration and contract.
UploadsPDF and DOCX files are written to the selected profile’s server-side uploads directory. Text is extracted and included in the Hermes request. Attached uploads are deleted in a finally block after completion, failure, or cancellation; manual cleanup is also available. Crash recovery, filesystem snapshots, infrastructure logs, and backup retention are deployment responsibilities and are not represented as immediate deletion.
Generated draftsGenerated DOCX files are stored in the profile’s generated directory so an authenticated user can download or send them. Older generated drafts are removed by the implemented cleanup workflow; customer retention begins after transfer to the customer’s controlled repository.
TelegramMessages pass through Telegram’s Bot API and the configured Hermes gateway. The dashboard transcript file retains up to the latest 500 message records at the configured server path. Telegram’s own processing is governed by the customer’s and Telegram’s applicable terms and configuration.
Email deliveryA draft is sent only after the user confirms the recipient and action. Delivery uses the configured Google Workspace MCP. Artifact metadata can record the recipient and delivery time; the receiving mailbox and Google Workspace retention are outside the dashboard’s deletion workflow.

Purpose and access

Data is processed to authenticate users, route requests, extract authorized evidence, generate drafts, restore operational state, deliver user-confirmed files, troubleshoot failures, and protect the service. Access should be limited to authorized operators and the services necessary for the requested workflow.

Requests and incidents

Use the ServicioXpert contact channel for privacy requests or suspected incidents. Do not assume HIPAA coverage or a business-associate relationship unless applicability has been assessed and the required written agreement is in effect.

Owner: MyZeusCompliance · reviewed 2026-08-18 · verify after provider, storage, logging, or deployment changes
Security

Implemented controls and boundaries

  • Protected operational APIs require authentication.
  • Hermes, Telegram, and dashboard credentials remain server-side.
  • Upload filenames and paths are constrained; file type and size are limited.
  • Downloads use private, no-store cache control.
  • HSTS, frame denial, MIME protection, restrictive referrer policy, and permissions policy are emitted.
  • Chat and login rate limits are implemented.

These controls reduce risk but are not a certification or guarantee. The current CSP permits inline scripts and styles. Deployment owners remain responsible for patching, backups, access review, monitoring, recovery, provider assurance, and incident response. Report a suspected vulnerability through the service contact without including exploit secrets or sensitive records.

Accessibility

WCAG 2.2 AA target

The service includes skip navigation, semantic controls, accessible names, reduced-motion support, keyboard tab navigation, and focus management for the requisition dialog. WCAG 2.2 AA is a target, not a current conformance claim.

Manual testing is still required for authenticated workflows, keyboard-only completion, zoom and reflow, contrast, errors, live regions, and representative screen readers. Report a barrier through the service contact, including the page, task, assistive technology, and browser where possible.

W3C Web Content Accessibility Guidelines 2.2

Terms of responsible use

Authorized drafting only

  • Use the service only with information and systems you are authorized to access.
  • Do not submit prohibited sensitive information under the current service boundary.
  • Verify all facts, citations, calculations, requirements, and acceptance criteria.
  • Do not treat a generated file as effective, executed, approved, validated, or released.
  • Move an approved final document into the authorized quality or document-management system.
  • Do not use the service to impersonate a regulator or fabricate evidence, signatures, approvals, or inspection results.
Disclaimer and independence

Advisory drafts, not delegated authority

MyZeusCompliance is an independent AI-assisted documentation service. It is not affiliated with, endorsed by, or acting for FDA, EMA, the European Commission, or another regulator. Named agents are workflow roles, not human reviewers or regulatory officials.

The service does not provide regulatory approval, legal advice, medical advice, certification, validation approval, product-release authorization, or a substitute for qualified professional review. Users determine applicable requirements and remain accountable for final decisions and records.

Editorial and correction policy

Primary evidence before summaries

Material regulatory content should state its jurisdiction, product or process scope, source type, publication or effective date, and primary link. Regulations, guidance, standards, enforcement communications, and MyZeusCompliance interpretation must remain distinguishable.

AI summaries and news feeds are decision support. Users must open the controlling record before CAPA, change control, submission, validation, product disposition, or another regulated decision. Material corrections are dated in the repository changelog and high-impact sources are rechecked after relevant authority updates.

Regulatory sources

Authoritative starting points

These links do not establish applicability or competence by themselves. The customer and qualified reviewers must determine the governing requirements for the intended use, jurisdiction, product, facility, and lifecycle stage.