Trust center

What we commit to our customers. Two-factor login is enforced on our company accounts. Customer data is encrypted in transit. Our production database is backed up automatically, and we regularly test that those backups restore. We monitor uptime and are alerted when the service goes down. Access to production follows least privilege, and production secrets are kept in a managed secrets store. Everyone on the team passes a background check, signs a confidentiality agreement and completes security training. We keep customer data only as long as our retention policy allows, and delete it when it is no longer needed. If a security incident affects your data, we tell you within 48 hours. We review the security reports of the vendors that handle customer data, and list them below. We review these commitments at least once a year.

Controls

Last verified 2026-09-27

Policies and Governance

  • Information security policy suite
  • Policy acknowledgment
  • Security roles and organization
  • Remediation tracking
  • Code of conduct
  • Customer security commitment
  • Internal security reporting channel

Risk Management

  • Annual risk assessment
  • Risk assessment on significant change

HR and Personnel

  • Background checks
  • Security awareness training
  • Confidentiality agreements
  • Onboarding access provisioning
  • Offboarding access revocation
  • Annual security responsibilities check-in

Access Control

  • Single sign-on and app inventory
  • Two-factor login enforcement
  • Two-factor login enrollment
  • Named accounts
  • Least privilege access
  • Password management
  • Secrets management
  • Managed devices
  • Device return and wipe
  • External access restrictions

Operations and Monitoring

  • Cloud audit logging
  • Logging coverage and retention
  • Security alerting
  • Endpoint malware protection

Change Management

  • Pipeline deployments
  • Emergency changes
  • Infrastructure change control

Incident Response

  • Incident response plan

Availability and Backup

  • Uptime monitoring and alerting
  • Automated backups
  • Backup restore testing
  • Business continuity plan

Confidentiality and Data

  • Encryption in transit
  • Data classification
  • Data retention and deletion

Vendor Management

  • Vendor management

Subprocessors

  • AnthropicSupported LLM inference provider for testing agents
  • CloudflarePublic edge/CDN and origin-fronting layer
  • Fly.ioApplication hosting, Machines, private networking, container registry, persisten
  • GitHubInstall the HackZero app, then pick the repositories this audit covers. We read
  • GoogleOAuth sign-in, Calendar/Meet scheduling, and Places lookup
  • Google GeminiSupported LLM inference provider for testing agents
  • Google WorkspaceRead-only: lists your users to prove two-factor login (Google's 2-Step Verificat
  • OpenAISupported OpenAI-compatible LLM inference endpoint/client
  • PostHogBrowser and server-side product/conversion analytics
  • ResendTransactional email delivery
  • SlackNotifications and applicant community invite
  • StripeIdentity verification, billing/subscriptions, Checkout/Portal, and Connect payou
  • TigrisS3-compatible object storage for backups, shipped logs, and operation workspaces

Security questions

founders@hackzero.ai

Get access to HackZero's documents

Accept once. Everything unlocks immediately, with no approval step.

By requesting access to confidential security documentation from HackZero, I agree to keep it confidential, to use it solely to evaluate HackZero as a vendor, and not to redistribute it. I consent to sign electronically and agree that my electronic signature has the same validity as a handwritten one.