Connect what you already run. Govern every call it makes.
The systems your team lives in, plus any MCP server your agents should reach, each one connected as the person asking, and checked before the call rather than reported after it.
The systems your work already lives in.
Every connection is governed the same way, whichever family it comes from, and a source your organisation has not approved simply is not there.
22,000+ apps already ship an MCP server. Yours are one governed connection away: ZeroH connects as the person asking, masks before any model, and puts every call on the ledger.
Connected natively today: 7 systems plus the Microsoft estate, 36 governed tools in the box. Not on the list? Ask: we ship new tools every day, and a connector you need is usually days away.
Triage the unread pile, draft a reply in the thread, never send without your yes.
LiveWhere the agents work: ask in a channel, get the answer and its receipt in the same place.
LiveA folder becomes a knowledge base; the folder’s own permissions decide who its answers reach.
LiveFind the free hour, prep the meeting, and know what was decided in the last one.
LiveDraft and redline in the document itself, with the sensitive parts masked before any model.
LiveBuild the deck from a project’s own context, in your brand kit.
LiveRead accounts and opportunities, log the activity, keep the record true, field by field.
LiveThe same governed CRM reads and writes, under each user’s own HubSpot authorisation.
Liveconnects with your own HubSpot OAuth appCommits, diffs and file reads under your own identity: only the repositories you can already see.
LiveWork items read as you: Atlassian’s own per-project visibility is the boundary, not ours.
LiveDocuments your team keeps in Drive, read under each person’s own Google authorisation.
LiveResearch a company or a market with the egress allow-listed and every fetch on the record.
LiveBlog and newsletter drafts land in your CMS as drafts, and the family cannot publish by construction.
LiveZeroH is the MCP client, connecting as the person asking, so the server’s own permissions still apply, and the result is masked and recorded before any model sees it.
LiveDeclare an endpoint as a governed tool: same masking, same approvals, same ledger as the built-in ones.
In buildthe console authoring flow is being built outA folder is a source too, that is how a shelf of documents becomes cited answers. Knowledge & Memory →
Anyone can connect a system. This is the part that decides what happens next.
A connection is not consent. Between an agent deciding to use a tool and the tool running, four things are settled, who may use it, what the model may ever see of it, who agreed, and whether a person has to say yes.
Not “the AI can use your CRM”. The Sales agent may look up an account because that is the work it was hired to do; the Help Desk agent cannot, because it was not. The grant is the pairing of an agent, a tool and the job it serves.
LiveConnecting a system does not hand it over. Each field carries its own rule, and anything you have not declared is masked rather than guessed, so a schema that grows on the vendor’s side cannot quietly widen what leaves your tenant.
The person reading the answer sees the real account name: it is rehydrated on your servers after the model is done. The model never had it.
Livelive for CRM today; the unified per-connector panel is in buildA read changes nothing: the worst case is that the agent knows something it did not need. An action leaves a mark outside ZeroH: someone receives the mail, the record changes, the money moves. So every tool is tiered low or high, and a high one never runs unattended unless you decided it may.
The job stops and waits as a card with the full context. Nothing is sent, written or spent until someone says yes.
You pre-approve the routine cases for that agent and that tool. It proceeds alone, and every run is still receipted.
Some actions are simply refused for that agent, whatever it decides. The refusal is the policy working, not a bug.
And when the case is not one you covered, the agent asks instead of guessing. The escalation goes to a person with the context attached.
LiveSaying yes to a new data source should not be an act of faith.
Add the connector, and before you say yes, see exactly what it would reach and which actions it would enable. Approve what you saw; nothing was reachable before that moment.
Add the connection and supply the credential. It lives in your key vault by reference, the token bytes never touch a store, a log, or the ledger.
ZeroH connects and asks the system what is actually there, instead of trusting a description of it.
You see the capability preview before you decide: the tables and records it would reach, and the agent actions it would enable.
You approve what you saw. Nothing was reachable before this moment, and the approval itself lands as a policy-change event.
In buildgoverned source reads through connectors are live; the console configure → probe → preview → approve flow is being built out
See exactly what the AI reads from each source.
Right where you connect a source, a panel will list its fields and what the model gets of each: tokenized, masked, or in the clear because reasoning needs it. Anything undeclared is masked, not guessed.
Masked by default
A field you never declared is masked, not guessed, so a schema that grows on the vendor’s side cannot quietly widen what the model sees. Fail closed is the default everywhere in ZeroH.
Plannedper-field structured masking is live for CRM today; the unified per-connector panel is the new pieceOne truth, two places to read it
The same rules show cross-cut across every connector in the Policy Center, and changing one is a versioned, audited write.