Skip to main content
Zerovyn
Services Products Trading Hunting Security Contact
Start a Project
Legal/Security

Security

This page describes the security measures Zerovyn has actually implemented for its public website and its delivery environment, and is equally clear about what has not been done or verified. Both lists matter; a security page that only lists achievements is not a security page.

What is in place

  • HTTPS everywhere. The entire site is served over TLS, and insecure requests are upgraded by content-security policy.
  • Blocked sensitive paths. Server rules deny public access to the submission ledger, to configuration files, and to anything matching internal file patterns.
  • Hardened HTTP headers. Content-type sniffing protection, frame-ancestry restriction, and a strict referrer policy are set on every response.
  • Server-side input validation. Every form field is length-capped and type-checked on the server before it is accepted. The browser's validation is convenience, not the control.
  • Rate limiting. The chat assistant is limited per IP address, so it cannot be abused as an open language-model endpoint.
  • Scope-limited assistant. The chat agent refuses requests outside its stated purpose and will not follow instructions that attempt to change its role.
  • No client-side secrets. Nothing a browser can read is a credential. Secrets used by the server are read from environment configuration, never from the served document tree.
  • Minimal third-party surface. The site loads fonts and its own assets. No advertising networks, no behavioural analytics, no third-party tag managers.
  • No cookie surface. Because the site sets no cookies, there is no cookie-based attack or tracking surface on it.
  • Secrets excluded from deployment. The publish pipeline has an explicit denylist: credentials, ledger files and server configuration are never uploaded with the static site.

What is deliberately not claimed

The following are not claimed, because Zerovyn has not obtained or verified them. They may be appropriate later; asserting them now would be misleading.

  • SOC 2, ISO 27001, PCI DSS or any other certification. Zerovyn holds none.
  • Formal penetration testing by an independent third party. This has not been commissioned.
  • A documented incident-response programme with named on-call rotation.
  • Continuous, 24/7 security monitoring.
  • Zero-trust architecture, or any named architectural certification.
  • Encryption of data at rest in a form we have independently verified. Hosting-level encryption is provided by the infrastructure, not by a control we operate.
  • Any government registration, licence or regulatory approval.

Responsible disclosure

If you find a security issue on this site, please report it responsibly. Send the detail to security@zerovyn.com, in private, without publishing it first. Give us a reasonable period to respond before any public disclosure. Every genuine report is acknowledged, investigated and fixed, and good-faith reporting is not treated as an attack.

What a report should contain

The affected URL, the steps that reproduce the issue, the impact you observed, and a way to reach you. That is enough to begin. Do not attempt to access, modify or exfiltrate data that is not yours while testing.

Scope of authorised testing

Testing the site's public defences against your own account of behaviour is fine. Unauthorised attempts to access other people's data, to disrupt availability, or to move laterally into hosting infrastructure are not authorised and are dealt with as an attack. See the acceptable use policy.

Effective  28 September 2026 Last updated  28 September 2026 Contact  security@zerovyn.com

Start a project

Built to ship.

Tell us the problem. We will tell you whether it should be AI, software, automation — or none of them.

sales@zerovyn.com contact@zerovyn.com

No mailing lists, no automated sequences. One reply, from a person, within 48h.

Zerovyn

Products

Trading Hunting Crypto — in development

Services

AI & Agents Product & SaaS Web & Interface Systems & Automation

Company

Products Security Start a Project Contact

Legal

Privacy Policy Terms Cookies Disclaimer

Payments

USDT / ETH (ERC-20) 0xcE83573CBfa4dE435FF2B4b2804a0cDdf027c6ab
Zerovyn Assistantonline

A Zerovyn assistant — here to answer what we build and how we work.