Security starts with clear boundaries.

This overview describes current product principles and implementation responsibilities. It does not claim certifications or guarantees that have not been independently verified.

Deployment boundary

Zy-AI and ZyStorage are designed for customer-managed or agreed dedicated environments. Deployment architecture, hosting responsibility, residency, backup, and recovery requirements must be documented for each engagement.

The licensing control plane verifies commercial entitlement. It is not intended to proxy customer files, prompts, documents, or model traffic.

Identity and access

  • Account-wide and workspace or organization roles remain separate.
  • Backend authorization, not interface visibility, must enforce access.
  • Managed accounts, customer identity providers, and hybrid policies are deployment choices.
  • Administrative and support access should be explicit, time-bound where applicable, and auditable.

Data protection

  • Use encrypted transport for all external traffic.
  • Protect persisted credentials with application encryption and controlled key handling.
  • Keep deployment identities and signing material on persistent, backed-up storage.
  • Define customer-specific retention, deletion, backup, and restore procedures before production use.

Secure operation

  • Apply supported product and dependency updates.
  • Restrict first-run setup and administrative endpoints from public access.
  • Centralize logs without recording passwords, secrets, signed URLs, or unnecessary customer content.
  • Test restoration, license renewal, account recovery, and administrator transfer before launch.

Shared responsibility

Product security also depends on the environment in which it runs. Customer and Zyqlo responsibilities should be written into the deployment plan, including identity ownership, network controls, encryption keys, backups, update windows, incident contacts, and recovery objectives.

Security requirements that are not yet independently verified must be described as planned controls, not certifications or guarantees.

Responsible reporting

To report a suspected security issue, email ava@zyqlo.com with the subject “Security Report.” Do not include active credentials, private keys, or unnecessary customer data in the first message.