Trust & Security
How ZeroLeaks handles, retains, and protects your data.1. Data handling
ZeroLeaks scans the system prompts and agent configurations you submit. We process this data only to run the security assessment you requested and to generate your report.
System prompts and prompt-derived content are redacted from stored reports: report findings, conversation excerpts, and remediation guidance have the original prompt text stripped before persistence.
2. Data retention
Scan scores, findings, recommendations, and remediation guidance are retained for the lifetime of your account so you can track posture over time.
Full scan transcripts and tool-execution logs are retained for a configurable window (default 365 days) and are automatically purged afterward by a scheduled job. You can shorten this window in Settings → Security → Data retention.
Deleting a scan or account removes the associated reports.
3. Sub-processors
We rely on a small set of infrastructure providers to deliver the service: Vercel (application hosting and ephemeral sandboxes), Convex (application database), OpenRouter (model inference for red-team and evaluation), Stripe (billing), and Resend (transactional email).
Each sub-processor receives only the data necessary to perform its function.
4. Security
Authentication supports passkeys and two-factor authentication. Sessions are scoped per device and can be revoked at any time.
Scan execution runs in isolated, ephemeral Firecracker microVM sandboxes that are destroyed after each scan.
5. Compliance & legal
A Data Processing Agreement (DPA) is available to customers on paid plans on request.
Our SOC 2 report and security questionnaire responses are available under NDA to enterprise customers. Contact us to request access.