Skip to content

Security at Zerod

Version 1.0Effective from 1 August 2026

We practise what we sell

Zerod builds compliance and security-validation software. It would be hard to justify not applying to our own systems the same rigour we ask of our customers.

This page describes our product security and how to report a vulnerability to us. We only claim here what we can stand behind: where a control is not yet formalised, we say so, rather than filling the gap with platitudes.

Certification

ISO/IEC 27001. Zerod is certified to ISO/IEC 27001:2022. The certificate is issued to Cybersec Hub, S.L., the company that trades as Zerod, and is published in our Trust Center.

StandardISO/IEC 27001:2022
Certification bodyACCM
StatusCurrent, issued 18 May 2026, valid until 6 July 2028
Registration codeSI-134826

Product security

The following is implemented and verifiable in our product:

  • Encryption of sensitive data. Integration credentials and sensitive content are encrypted with AES-256. The system fails closed: if the encryption key is unavailable, the operation stops rather than proceeding unprotected. There is no fallback key embedded in the code.
  • Confidentiality of the most sensitive data. In the whistleblowing channel, the body of each report and its attachments are stored encrypted, and access is restricted to the strictly authorised roles.
  • Role-based access control, built on explicitly granted permissions (never by default), with separation between organisations.
  • Segregation between internal services. Communication between our internal components is authenticated with a shared secret using constant-time comparison, and also fails closed on an authentication failure.
  • Least privilege in the database. Services access data with reduced-permission roles, limited to what each one needs.
  • Automated tests as a deployment gate: changes are not released unless they pass the test suite.
  • Platform penetration testing. The Zerod platform undergoes annual penetration testing carried out by our own vetted hacker network, alongside continuous PentAI validation. Independent third-party testing is not part of the current programme: this is a deliberate position, as Zerod delivers this service itself. The detail of each test, including its dates, belongs in the Trust Center and not in this document.

How we built the Trust Center — and why it matters here

This is the control we are proudest of, because it applies to us too.

Our product generates each customer's Trust Center and security-posture cards. We designed it with honesty rules encoded into the product itself: it does not show claims in the negative, it does not describe a practice as "annual" without at least two dated tests to back it, and it hides an entire section if no data supports it. This is covered by automated tests that verify it.

Put differently: we built our transparency tool so that it cannot inflate a security posture — not even ours. Those rules govern what the product publishes on a customer's Trust Center; this page is governed by the same principle.

Infrastructure

Our platform runs on Google Cloud Platform, with data hosted in the European Union. We apply privilege separation between services and encryption of data in transit and at rest.

Current details of our posture, together with the certification, are available in our Trust Center.

Responsible disclosure

If you have found a vulnerability in our systems, we want to know. This is the channel.

How to report

Email: security@zerod.io

Where possible, include: a description of the vulnerability, the affected system or URL, reproduction steps, estimated impact and supporting evidence.

Our commitment

Status updatesRegular updates until resolution
RecognitionIf you wish, we will credit you as the reporter

We will not pursue legal action against anyone who researches and reports in good faith while respecting this policy.

We do not currently operate a paid bug bounty programme.

Scope

In scope: zerod.io, ciso.zerod.io, app.zerod.io and infrastructure directly managed by Zerod.

Out of scope: third-party services; social engineering against our staff or our customers'; denial-of-service attacks; physical attacks; automated findings without demonstrated impact; missing security headers without an associated exploitation vector.

Rules

  • Do not access, modify or extract data that is not yours. If you encounter personal data, stop and tell us.
  • Do not degrade or interrupt the service.
  • Do not publicly disclose the finding until we have fixed it or 90 days have elapsed since your report.
  • Comply with applicable law.

Security contact for customers

If you are a customer and need to report or raise a security incident affecting you, use the channel set out in your contract or write to security@zerod.io.

Language

This document is published in Spanish and English. In the event of any discrepancy between the two versions, the Spanish version shall prevail.

Version history

VersionDateChanges
1.02026-08-01First publication. Replaces the ISMS policy previously published at /terms-and-conditions/information-security-policy, which was an uncompleted template and has been withdrawn.
Security at Zerod · Zerod