Security at Zentrix
Last updated: July 19, 2026
1. Our Approach to Security
Zentrix is an AI store builder — merchants trust us with their business data and their storefronts' payment flows. That trust is the product. This page describes the technical and organizational measures we use to protect it, in plain language.
It is a description of our current practices, not a compliance attestation. Where the legal detail matters — data rights, retention, transfers — the Privacy Policy is the authoritative document.
2. Data Protection & Encryption
In transit. All traffic between your browser and Zentrix is encrypted with TLS (HTTPS). We do not serve any part of the platform over unencrypted connections.
At rest. Account data, the prompts you submit, and the content you generate are encrypted at rest on our cloud infrastructure.
Data residency. Your data is stored in the United States on managed cloud infrastructure. Details on international transfers and the safeguards we rely on are in our Privacy Policy.
3. Infrastructure & Hosting
Zentrix runs on established managed cloud providers — Vercel for the application and Supabase for the database — rather than self-operated servers, inheriting their physical security, network isolation, and platform hardening. Databases are backed up automatically so we can recover from failures.
4. Access Control
- Least privilege — internal access to production systems is limited to the people who need it to operate the service.
- Strong authentication — access to internal systems requires strong authentication.
- Admin limits — administrative access to customer data is restricted and used only to operate and support the Services.
5. Payment Security
All payments are processed by Stripe, a certified PCI-DSS Level 1 service provider. Card details go directly from your browser to Stripe — Zentrix never stores raw card numbers on our servers.
6. Application Security
- Dependencies are monitored and patched when security updates are released.
- Code changes go through review and automated checks before deployment.
- We log and monitor production systems to detect anomalous activity.
7. Compliance Posture
We believe in being straight with you: Zentrix does not currently hold formal certifications such as SOC 2 or ISO 27001. We are an early-stage product, and instead of badges we describe our real practices on this page — and will update it if that changes. Our data-handling practices are designed to align with GDPR and CCPA/CPRA; see the Privacy Policy for the specifics and your rights.
8. Sub-processors
We rely on a small set of vendors to run Zentrix — payments (Stripe), hosting and infrastructure (Vercel, Supabase), analytics, email, and AI providers (Anthropic, Recraft AI). The canonical, always-current list — including what each provider is used for — lives in Privacy Policy §6: Sub-processors, so the two pages never drift apart.
9. Reporting a Vulnerability
If you believe you've found a security vulnerability in Zentrix, we want to hear about it. Email security@gozentrix.com with:
- A description of the issue and its potential impact.
- Steps to reproduce it, including any relevant URLs or payloads.
- How we can reach you for follow-up questions.
We will acknowledge your report promptly, keep you informed as we investigate and fix the issue, and will not take action against good-faith research that respects user data and service availability. Please avoid accessing other users' data, degrading the service, or publicly disclosing an issue before we have had a reasonable opportunity to address it.
10. Availability & Status
Current uptime and incident history are published on our status page.
11. Incident Notification
If we learn of a breach affecting your personal data, we will notify affected users and regulators as required by applicable law, without undue delay.
12. Contact
Security questions or reports: security@gozentrix.com.
This page describes Zentrix's current security practices and is provided for transparency; it is not a certification or a contractual commitment.
Security Contact
Found a vulnerability or have a security question? Contact us at: security@gozentrix.com