Transparent, accountable platform security.
We separate what is active today from environment-dependent settings and planned roadmap items so you can make informed decisions about your code and data.
Active Security Controls
These protections are enforced across every Zentara project by default.
Authenticated Account Isolation
Strict database record scoping and cryptographically signed session tokens. Projects, files, and chat records cannot be queried or mutated across customer accounts.
Gated Review & Approval Controls
AI builds stage changes in isolation. No modifications are applied to your project's accepted source files without explicit customer approval.
Continuous Checkpoints & Rollback
Immutable pre-build snapshots are saved before every task execution, allowing instantaneous recovery if a build introduces unexpected behavior.
Automatic Secret Redaction
Database URLs, session tokens, and provider API keys are scrubbed from terminal outputs, git diff logs, and diagnostic audit payloads before rendering.
Protected Server API Endpoints
All project manipulation, file read/write, and AI job execution routes validate user ownership and active project status before execution.
Isolated Micro-VM Sandboxes
Project runtimes execute in dedicated micro-VM container environments segregated from other customer workloads and control planes.
Infrastructure Context
These settings depend on your deployment configuration and connected cloud services.
Custom Domain TLS & SSL
HTTPS certificates and edge TLS termination depend on your chosen hosting provider (e.g. Vercel, Cloudflare, or AWS) and DNS configuration.
External Provider Secret Storage
When connecting third-party services (such as Neon PostgreSQL or GitHub), credentials reside in project-level encrypted vaults governed by provider availability.
Sandbox Container Egress Rules
Container internet access during npm package installation is bounded by container provider network security policies and repository access permissions.
Upcoming Enhancements
Security features currently in design and architecture validation.
Enterprise SSO & SAML Integration
Planned support for Okta, Google Workspace, and Azure AD single sign-on for enterprise team workspaces.
SOC 2 Type II Compliance Certification
We are establishing operational controls and audit logging frameworks in preparation for formal third-party SOC 2 compliance evaluation.
Customer-Managed Encryption Keys (CMEK)
Future support for encrypting project file snapshots and database volumes with customer-controlled KMS keys.
Have specific compliance or enterprise security questions? Contact our team at contact support.