Zaro
Also known as: Zaro, zaro.ai, Zaro AI
Shared context layer for enterprise AI: company knowledge held as versioned, permissioned files that people and agents read from and write back to, with approval gates and a full action trail.
Zaro is a context layer for enterprise AI. It holds one current, attributable account of how a business runs, kept as plain readable files such as Markdown and YAML rather than rows behind an API. Nothing is overwritten: every file keeps its version history, can be read as it stood on any past date and restored in one step, and every answer names the file and version it came from. Agents read from the layer and write back what they learn, so the output of one run becomes the input of the next.
Context arrives through more than 120 native connectors, among them SharePoint, Microsoft 365, Teams, Salesforce, Confluence, Jira, Slack, Snowflake, Databricks, Google Drive and HubSpot. There is also an API for systems a customer built itself, an open agent protocol that lets outside agents read what they are cleared for and write back, and a governed browser session for systems with no API at all.
Access is set per folder path as read, write or deny, and it applies equally to people and automated work. Every agent runs under a scoped service account that can never exceed the permissions of the person who created it. Agents must ask for approval before deleting data, calling paid third party services or running irreversible operations, and the request goes out by email and Slack and times out as denied after 30 minutes. Reads, writes and tool calls are logged with the user, workflow, source context and outcome, and code runs only in isolated sandboxes.
The trust center states ISO 27001 certification and SOC 2 Type II in progress, with an observation period that ran June to September 2026. It also documents enterprise SSO over SAML and OIDC and production on AWS in London with a Frankfurt recovery site. Model work is routed across several providers, including Anthropic, OpenAI, Google and a default open weights model served by Fireworks AI.
Vendor details
Canonical URL
https://zaro.ai/
Category
Agent infrastructure
Subcategory
Shared context and memory layer for enterprise agents
Funding status
5.1M USD pre seed (June 2026) led by Cherry Ventures; angels include Thomas Wolf and Thomas Dohmke
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
More than 120 native connectors including SharePoint, Microsoft 365, Teams, Outlook, Salesforce, Confluence, Jira, Slack, Snowflake, Databricks, Google Drive and HubSpot, read with permissions intact. Also an API for custom systems, an open agent protocol for outside agents, and a governed browser session for systems with no API. Third party OAuth runs through Composio.
In practice
A retail chain cannot say why one northern store outperforms its region. Zaro joins sales, footfall, pricing, client feedback and market signals across stores and explains the drivers, citing the file behind each conclusion.
A sales leader wants to know what the top rep does differently. Zaro reads calls, emails and deals, surfaces the pattern and writes it into a versioned playbook the team coaches from.
An operations team wants outside agents working from company context without seeing finance or HR files. Zaro grants read on the playbook paths, denies the rest, and logs every read and write.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
10.0 / 14 capabilities · 71%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents take authenticated action in outside systems: 120 plus native connectors read with permissions intact, third party OAuth and API orchestration through Composio, and a governance layer that scopes tool actions (read, write, send, move, generate) per connection, with a guardrail example that denies sending email from Gmail. Zaro platform, security and trust pages, 29 Sep 2026. Sourcezaro.ai/securityread 2026-09-29 |
|
| Workflow Orchestration | Partial |
|
Agents run work against the shared context and each run writes files the next run reads, but no workflow model is documented on the pages read: no sequencing, branching, retries or multi agent routing, and the vendor positions itself against workflow wiring in its own n8n comparison. Zaro platform page and Zaro vs n8n page, 29 Sep 2026. Sourcezaro.ai/platformread 2026-09-29 |
|
| Knowledge Grounding & RAG | Full |
|
A maintained retrieval structure persists over the customer knowledge: context is held as versioned files in PostgreSQL and S3 with OpenSearch search and vector indices mirrored from them, fed by 120 plus connectors, and every answer names the file and version it came from. Zaro platform page and trust center, 29 Sep 2026. Sourcezaro.ai/platformread 2026-09-29 |
|
| Human Oversight & Guardrails | Full |
|
Vendor shipped approval mechanism: a built in ask_permission tool requires user approval before agents delete data, call paid third party APIs or run irreversible operations; requests route by email and Slack and time out as denied after 30 minutes, workspace managers tune the defaults per agent, and a policy layer returns allow, escalate or block on tool calls. Zaro trust center and security page, 29 Sep 2026. Sourcezaro.ai/trustread 2026-09-29 |
|
| Security, Identity & Governance | Full |
|
Access surface: enterprise SSO over OIDC and SAML with an SSO only option, per path read, write or deny rules enforced equally for users, agents and MCP clients, and agents on scoped service accounts that cannot exceed their creator. Compliance posture: ISO 27001 stated as certified, SOC 2 Type II in progress through Drata (observation period 1 June to 1 September 2026, report pending); registrar and certificate number not published. Zaro trust center, 29 Sep 2026. Sourcezaro.ai/trustread 2026-09-29 |
|
| Observability & Auditability | Full |
|
Runtime audit of agent actions: reads, writes and external tool calls trace to the user, workflow, source context and outcome; each tool audit record carries provider, status, safety level, latency, timestamp and full command input; history is exportable and file versions name the agent that last edited them. Retention stated at 30 days for application logs and 90 days for events. Zaro security page and trust center, 29 Sep 2026. Sourcezaro.ai/securityread 2026-09-29 |
|
| Memory & State Persistence | Full |
|
A documented memory layer with stated scope and lifetime: agents write back what they learn into the shared context, a reserved workspace memory path is protected from generic write tools, scope is set per folder path, and file versions are retained per workspace policy, readable as of any past date and restorable. Lifetime is stated as workspace policy rather than a fixed duration, hence medium. Zaro platform page and trust center, 29 Sep 2026. Sourcezaro.ai/platformread 2026-09-29 |
|
| Deployment & Data Residency | Partial |
|
Production runs on AWS London with a Frankfurt recovery site, a fact about the vendor infrastructure rather than a selectable region, which alone is None; the Partial rests on dedicated BAA ready deployments offered on request for healthcare. No VPC, on premises, self hosted or region selection option is documented, and model inference leaves the region for US and globally routed LLM sub processors. Zaro trust center and getting started page, 29 Sep 2026. Sourcezaro.ai/trustread 2026-09-29 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Assets are assembled per customer rather than adopted from a catalog: the pilot scopes one use case on the customer data with the vendor, and the homepage shows three worked use cases (retail, go to market, distributed operations). June 2026 launch coverage describes an app store and marketplace of preconfigured workflows, but no catalog appears on the pages read. Zaro getting started page and homepage, 29 Sep 2026. Sourcezaro.ai/getting-startedread 2026-09-29 |
|
| Triggers & Channel Coverage | Unable to verify |
|
No schedules, webhooks, event triggers or inbound queues are documented on the platform, security, trust, getting started or comparison pages; the platform graphic of three runs one week apart illustrates compounding rather than a documented schedule, and approval notices by email and Slack are outbound. No public documentation site exists to check, hence low. Zaro platform page and trust center, 29 Sep 2026. Sourcezaro.ai/platformread 2026-09-29 |
|
| Model Flexibility & Routing | Partial |
|
Vendor internal multi provider routing: the sub processor list names Anthropic, OpenAI, Google Gemini (optional), a default GLM family model served by Fireworks AI through the Requesty gateway, and OpenRouter for fallback routing. Customer or admin control of model choice and bring your own key are not documented; the word optional on Gemini is the near miss. Zaro trust center, 29 Sep 2026. Sourcezaro.ai/trustread 2026-09-29 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
An API to read and write the context and an open agent protocol through which outside agents read what they are cleared for and write back are both stated, and API keys are issued once and stored as hashes, but no API reference, endpoint, auth documentation or enumerated tool list was located publicly. Missing: a documented API or SDK reference. Zaro platform page and trust center, 29 Sep 2026. Sourcezaro.ai/platformread 2026-09-29 |
|
| Testing, Debugging & Optimization | Partial |
|
The pilot runs one use case beside the existing process against success criteria agreed up front and measures before and after, but as a fixed fee engagement rather than a surface the customer invokes; in product, version diffs, restore and blocked action and error monitoring support debugging. No evaluation harness, scored tests or quality gates are documented. Zaro getting started, platform and security pages, 29 Sep 2026. Sourcezaro.ai/getting-startedread 2026-09-29 |
|
| Browser & Computer Use | Full |
|
A hosted browser the vendor runs: for systems with no API, agents work through a governed browser session, and the sub processor list names Browserbase for isolated cloud browser sessions used for agent driven web automation. The product page scopes the session to reading what it is cleared for, so actions taken through the browser are not separately documented, hence medium. Zaro platform page and trust center, 29 Sep 2026. Sourcezaro.ai/platformread 2026-09-29 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Not public · fixed fee pilot
fixed fee pilot, then annual enterprise contract, not per seat
What is public
The purchase path and its shape: a fixed fee pilot tied to deliverables, then an annual enterprise contract that is not priced per seat. No figures.
Billing mechanics
Pilot fee fixed and tied to deliverables, with success criteria agreed before building and a convert, expand or stop decision at day 30. Enterprise contract annual and scoped to the customer estate.
Cost watchouts
Model inference runs through several third party providers; whether heavy agent usage changes the annual price is not stated.
Variable cost rationale
The pilot fee is fixed and the enterprise contract is annual and not per seat, so cost is set once signed, but the contract is scoped to the customer estate with no published unit, and no usage, connector or overage terms are published.
Additional watchouts
No published unit, so cost cannot be modeled before a call.
Sales call required
Yes, required for paid access
Free / trial
No free tier or trial; a paid pilot with a decision at day 30
Lowest paid plan
Pilot (fixed fee, not published)
Commercial notes
If the customer stops at day 30 it keeps the pilot use cases, the documentation and the before and after measurement.
Key ambiguities
Whether the annual enterprise price scales with connectors, data volume, users or model usage is not stated.
Missing data
Pilot fee, enterprise contract range, what drives the annual price, any usage limits or overage terms.