Draft faster.
Keep human authority.
MyZeusCompliance generates structured draft protocols and quality documents through WebChat and Telegram Chat. AI assists authorship and evidence organization; authorized professionals remain responsible for verification, execution, approval, release decisions, and record control.
Current sensitive-data boundary: Do not submit PHI, patient-identifiable data, credentials, regulated originals, or confidential material your organization has not authorized for external processing.
Privacy and data handling
Observed production data flow
| Public dashboard | The public shell can store theme, route, session identifiers, and limited chat/news interface state in browser local storage. The visitor counter stores an aggregate count; the public shell does not set a session cookie. |
| Authentication | Protected WebChat, Telegram history, upload, document, and operational APIs require a server session. The session token is issued as an HttpOnly, SameSite=Strict cookie and is marked Secure when the reverse proxy reports HTTPS. |
| WebChat | The request text, session identifier, selected profile, and extracted content from attached PDF or DOCX files are sent through the configured self-hosted Hermes OpenAI-compatible gateway. Hermes can route the request to specialist profiles and its configured model provider. The dashboard repository cannot prove that upstream provider’s retention or training policy; the deployment owner must verify the active Hermes provider configuration and contract. |
| Uploads | Up to five PDF or DOCX files per request, at most 25 MB each. Files are written to the selected profile’s server-side uploads directory. Text is extracted and included in the Hermes request. Attached uploads are deleted in a finally block after completion, failure, or cancellation; manual cleanup is also available. Crash recovery, filesystem snapshots, infrastructure logs, and backup retention are deployment responsibilities and are not represented as immediate deletion. |
| Generated drafts | Generated DOCX files are stored in the profile’s generated directory so an authenticated user can download or send them. Older generated drafts are removed by the implemented cleanup workflow; the cleanup cadence is deployment-configured and can be confirmed in writing on request. Customer retention begins after transfer to the customer’s controlled repository. |
| Telegram | Messages pass through Telegram’s Bot API and the configured Hermes gateway. The dashboard transcript file retains up to the latest 500 message records at the configured server path. Telegram’s own processing is governed by the customer’s and Telegram’s applicable terms and configuration. |
| Email delivery | A draft is sent only after the user confirms the recipient and action. Delivery uses the configured Google Workspace MCP. Artifact metadata can record the recipient and delivery time; the receiving mailbox and Google Workspace retention are outside the dashboard’s deletion workflow. |
Purpose and access
Data is processed to authenticate users, route requests, extract authorized evidence, generate drafts, restore operational state, deliver user-confirmed files, troubleshoot failures, and protect the service. Access should be limited to authorized operators and the services necessary for the requested workflow.
Jurisdictions and written terms
Do not assume HIPAA business-associate coverage, EU/UK GDPR processor terms (including SCCs), or CCPA/CPRA service-provider terms unless applicability has been assessed for your data and the required written agreement is in effect. No such agreement is implied by using the public site or the chat gate.
Requests and incidents
Use the ServicioXpert portfolio contact (accountable owner: Luis Reyes) for privacy requests or suspected incidents.
Accountable owner: Luis Reyes · ServicioXpert · reviewed 2026-10-06 · verify after provider, storage, logging, or deployment changes
Security
Implemented controls and boundaries
- Protected operational APIs require authentication.
- Hermes, Telegram, and dashboard credentials remain server-side.
- Upload filenames and paths are constrained; file type and size are limited.
- Downloads use private, no-store cache control.
- HSTS, frame denial, MIME protection, restrictive referrer policy, and permissions policy are emitted.
- Chat and login rate limits are implemented.
These controls reduce risk but are not a certification or guarantee. The current CSP permits inline scripts and styles; tightening to nonce-based script and style delivery is a tracked roadmap item, and no independent third-party security assessment has been performed. Deployment owners remain responsible for patching, backups, access review, monitoring, recovery, provider assurance, and incident response. Report a suspected vulnerability through the accountable owner contact without including exploit secrets or sensitive records.
Accessibility
WCAG 2.2 AA target
The service includes skip navigation, semantic controls, accessible names, reduced-motion support, keyboard tab navigation, and focus management for the requisition dialog. WCAG 2.2 AA is a target, not a current conformance claim.
Manual testing is still required for authenticated workflows, keyboard-only completion, zoom and reflow, contrast, errors, live regions, and representative screen readers. A scheduled manual assistive-technology assessment will precede any conformance claim; when completed, this statement will be replaced with a dated report of the actual scope and results. Report a barrier through the accountable owner contact, including the page, task, assistive technology, and browser where possible.
W3C Web Content Accessibility Guidelines 2.2
Terms of responsible use
Authorized drafting only
- Use the service only with information and systems you are authorized to access.
- Do not submit prohibited sensitive information under the current service boundary.
- Verify all facts, citations, calculations, requirements, and acceptance criteria.
- Do not treat a generated file as effective, executed, approved, validated, or released.
- Move an approved final document into the authorized quality or document-management system.
- Do not use the service to impersonate a regulator or fabricate evidence, signatures, approvals, or inspection results.
Disclaimer and independence
Advisory drafts, not delegated authority
MyZeusCompliance is an independent AI-assisted documentation service operated by ServicioXpert (accountable owner: Luis Reyes · portfolio.servicioxpert.com). It is not affiliated with, endorsed by, or acting for FDA, EMA, the European Commission, or another regulator. Named agents are workflow roles, not human reviewers or regulatory officials.
The service does not provide regulatory approval, legal advice, medical advice, certification, validation approval, product-release authorization, or a substitute for qualified professional review. Users determine applicable requirements and remain accountable for final decisions and records.
Editorial and correction policy
Primary evidence before summaries
Material regulatory content should state its jurisdiction, product or process scope, source type, publication or effective date, and primary link. Regulations, guidance, standards, enforcement communications, and MyZeusCompliance interpretation must remain distinguishable.
AI summaries and news feeds are decision support. Users must open the controlling record before CAPA, change control, submission, validation, product disposition, or another regulated decision. Material corrections are dated in the repository changelog and high-impact sources are rechecked after relevant authority updates.
Regulatory sources
Authoritative starting points
Binding requirements (read the codified text)
Official guidance and interpretation
Standards and international references
These links do not establish applicability or competence by themselves. The customer and qualified reviewers must determine the governing requirements for the intended use, jurisdiction, product, facility, and lifecycle stage.
Last verified 2026-10-06 · Recheck after Federal Register, EudraLex, ICH, or PIC/S updates