Security
Last updated · May 13, 2026
Keeping your data secure is important to us. This page outlines how we approach security at Zeroset.
For any security-related questions, feel free to contact us at hello@zeroset.com.
Certifications and Third-Party Assessments
Zeroset is currently undergoing a SOC 2 Type II audit. We are committed to achieving and maintaining compliance with industry-standard security frameworks.
Infrastructure Security
Our infrastructure is primarily hosted on Amazon Web Services (AWS). All servers are in the United States.
- All data is encrypted at rest and in transit (TLS enforced).
- Database and compute resources are deployed within a private VPC. No databases are publicly accessible.
- Infrastructure access is scoped with least-privilege IAM policies.
We assign infrastructure access to team members on a least-privilege basis and enforce multi-factor authentication for AWS.
Data Security
- Tenant isolation: Row-level security enforces strict data isolation between workspaces, preventing cross-tenant data access.
- Encryption: All data is encrypted at rest and in transit. All API traffic is served over HTTPS.
- Credential security: Passwords and API keys are hashed before storage and never stored in plaintext.
AI Requests
To provide its features, Zeroset sends AI requests to language model providers. When you interact with Zeroset, your queries and relevant context are sent to our infrastructure on AWS and then routed to the appropriate model provider (Azure OpenAI, OpenAI, Google Cloud Vertex AI, Groq, or Modal).
We select model providers based on the task at hand.
All requests to model providers are made over encrypted connections. We do not use customer data to train models.
Account Deletion
You can delete your account at any time from your account settings. Deleting your account removes all associated data, including memories, collections, conversations, API keys, and any stored files. Deletion is cascading and permanent.
Vulnerability Disclosures
If you believe you have found a vulnerability in Zeroset, please submit the report to us at hello@zeroset.com.
We commit to acknowledging vulnerability reports within 5 business days and addressing them as soon as we are able to.