Encryption in transit
TLS for all external traffic to and from Zerg Cloud.
Security & Trust
Zerg is an early-stage company. We have a small set of security practices in place today, and a longer list of things we have not built yet. This page is the honest version of both — so your security team can decide whether the fit is right for now or better later.
What is in place today
Each item below is a concrete capability we operate today. If it is not listed here, assume we have not built it yet — and ask us directly if it matters for your evaluation.
TLS for all external traffic to and from Zerg Cloud.
Customer data — repositories, agent transcripts, generated artifacts, metadata — is stored on encrypted-at-rest infrastructure provided by our cloud host.
Zerg does not train models on customer code, prompts, agent transcripts, or runtime data. Customer data is used to operate the service for that customer and nothing else.
Customer payment processing routes through Stripe. Zerg does not store cardholder data and PCI DSS scope does not apply to us directly.
What is not yet
We do not currently hold SOC 2, ISO 27001, or any other third-party security certification. We do not have a HIPAA BAA available, and we are not a HIPAA Business Associate. We do not offer customer-managed encryption keys, single-tenant dedicated instances, or BYOC / VPC deployment.
If any of the above is required for your team to use the product, the most useful thing we can do today is tell you directly so you can plan accordingly.
Regulated industries
If you are evaluating Zerg from a healthcare, financial services, public sector, or other regulated context, please reach out before opening procurement. We will tell you what we can and cannot support today, and where we expect to be in the next few quarters.
We would rather have a short, honest conversation now than have your team find out at the questionnaire stage that we are not the right fit yet.
Get started