Trust center
What we commit to our customers. Two-factor login is enforced on our company accounts. Customer data is encrypted in transit. Our production database is backed up automatically, and we regularly test that those backups restore. We monitor uptime and are alerted when the service goes down. Access to production follows least privilege, and production secrets are kept in a managed secrets store. Everyone on the team passes a background check, signs a confidentiality agreement and completes security training. We keep customer data only as long as our retention policy allows, and delete it when it is no longer needed. If a security incident affects your data, we tell you within 48 hours. We review the security reports of the vendors that handle customer data, and list them below. We review these commitments at least once a year.
Controls
Last verified 2026-09-27Policies and Governance
- Information security policy suite
- Policy acknowledgment
- Security roles and organization
- Remediation tracking
- Code of conduct
- Customer security commitment
- Internal security reporting channel
Risk Management
- Annual risk assessment
- Risk assessment on significant change
HR and Personnel
- Background checks
- Security awareness training
- Confidentiality agreements
- Onboarding access provisioning
- Offboarding access revocation
- Annual security responsibilities check-in
Access Control
- Single sign-on and app inventory
- Two-factor login enforcement
- Two-factor login enrollment
- Named accounts
- Least privilege access
- Password management
- Secrets management
- Managed devices
- Device return and wipe
- External access restrictions
Operations and Monitoring
- Cloud audit logging
- Logging coverage and retention
- Security alerting
- Endpoint malware protection
Change Management
- Pipeline deployments
- Emergency changes
- Infrastructure change control
Incident Response
- Incident response plan
Availability and Backup
- Uptime monitoring and alerting
- Automated backups
- Backup restore testing
- Business continuity plan
Confidentiality and Data
- Encryption in transit
- Data classification
- Data retention and deletion
Vendor Management
- Vendor management
Subprocessors
- AnthropicSupported LLM inference provider for testing agents
- CloudflarePublic edge/CDN and origin-fronting layer
- Fly.ioApplication hosting, Machines, private networking, container registry, persisten
- GitHubInstall the HackZero app, then pick the repositories this audit covers. We read
- GoogleOAuth sign-in, Calendar/Meet scheduling, and Places lookup
- Google GeminiSupported LLM inference provider for testing agents
- Google WorkspaceRead-only: lists your users to prove two-factor login (Google's 2-Step Verificat
- OpenAISupported OpenAI-compatible LLM inference endpoint/client
- PostHogBrowser and server-side product/conversion analytics
- ResendTransactional email delivery
- SlackNotifications and applicant community invite
- StripeIdentity verification, billing/subscriptions, Checkout/Portal, and Connect payou
- TigrisS3-compatible object storage for backups, shipped logs, and operation workspaces