Skip to content

Trust Center

Trust is an artifact, not a promise.

This page states what we hold, what we are working toward, and how to reach us when something is wrong.

Security posture

How the products handle your data.

Architecture

Every ZHASK product deploys inside the customer's boundary. There is no multi-tenant data plane holding customer configuration or findings.

Data handling

Scanned data — configuration, findings, evidence — is written to storage the customer owns. ZHASK systems never receive it.

Read-only guarantee

Scanning is read-only everywhere: kaveo and Vectasec collect through read-only roles whose policies are published and diffable. Two capabilities go further, and both are opt-in. kaveo can draft and apply remediations, which requires a separate write role and stays a dry run until you explicitly enable an executor. aegis is an inline gateway that authorizes and blocks tool calls in the request path, though it never writes to the servers behind it.

Compliance

Status, stated honestly.

FrameworkStatusNotes
SOC 2 Type IIIn progressAudit window opened Q2 2026. Report available to customers under NDA when issued.
SOC 2 Type ICompleteIssued 2026. Available to prospects under NDA.
ISO 27001Not yet pursuedPlanned after SOC 2 Type II. We will not imply it before we hold it.
GDPRBy architectureProducts process customer data inside the customer's own environment; ZHASK is not a processor for scanned data.

Responsible disclosure

Found something? Tell us. We answer.

Report suspected vulnerabilities in any ZHASK product or in zhask.io to security@zhask.io. Include reproduction steps and impact as you understand it.

We acknowledge within 48 hours, give a substantive assessment within 7 days, and credit reporters who want credit once a fix ships. We do not pursue researchers who act in good faith: no testing against customers, no data exfiltration beyond proof, no service disruption.

Machine-readable details live at /.well-known/security.txt.

Subprocessors

Who touches ZHASK company data.

Product deployments involve no subprocessors — scanned data stays in your environment. The list below covers ZHASK’s own business operations.

VendorPurposeRegion
Amazon Web ServicesHosting for zhask.io and internal systemsUS
Google WorkspaceEmail and internal documentsUS/EU
GitHubSource control and release distributionUS

Build provenance and release signatures: github.com/zhask