Security & Trust Architecture

Transparent, accountable platform security.

We separate what is active today from environment-dependent settings and planned roadmap items so you can make informed decisions about your code and data.

Available Now in Production

Active Security Controls

These protections are enforced across every Zentara project by default.

Authenticated Account Isolation

Strict database record scoping and cryptographically signed session tokens. Projects, files, and chat records cannot be queried or mutated across customer accounts.

Gated Review & Approval Controls

AI builds stage changes in isolation. No modifications are applied to your project's accepted source files without explicit customer approval.

Continuous Checkpoints & Rollback

Immutable pre-build snapshots are saved before every task execution, allowing instantaneous recovery if a build introduces unexpected behavior.

Automatic Secret Redaction

Database URLs, session tokens, and provider API keys are scrubbed from terminal outputs, git diff logs, and diagnostic audit payloads before rendering.

Protected Server API Endpoints

All project manipulation, file read/write, and AI job execution routes validate user ownership and active project status before execution.

Isolated Micro-VM Sandboxes

Project runtimes execute in dedicated micro-VM container environments segregated from other customer workloads and control planes.

Environment & Provider Dependent

Infrastructure Context

These settings depend on your deployment configuration and connected cloud services.

Custom Domain TLS & SSL

HTTPS certificates and edge TLS termination depend on your chosen hosting provider (e.g. Vercel, Cloudflare, or AWS) and DNS configuration.

External Provider Secret Storage

When connecting third-party services (such as Neon PostgreSQL or GitHub), credentials reside in project-level encrypted vaults governed by provider availability.

Sandbox Container Egress Rules

Container internet access during npm package installation is bounded by container provider network security policies and repository access permissions.

Planned Security Roadmap

Upcoming Enhancements

Security features currently in design and architecture validation.

Enterprise SSO & SAML Integration

Planned support for Okta, Google Workspace, and Azure AD single sign-on for enterprise team workspaces.

SOC 2 Type II Compliance Certification

We are establishing operational controls and audit logging frameworks in preparation for formal third-party SOC 2 compliance evaluation.

Customer-Managed Encryption Keys (CMEK)

Future support for encrypting project file snapshots and database volumes with customer-controlled KMS keys.

Have specific compliance or enterprise security questions? Contact our team at contact support.