Security & Trust

Security information for your evaluation.

Review the practices and current limits below when evaluating Zerg for your systems. Contact our team to discuss requirements for your project.

What is in place today

Current practices.

These are the practices described for the hosted service today. Contact us for details relevant to your deployment and data.

Encryption in transit

TLS for all external traffic to and from Zerg Cloud.

Encryption at rest

Customer data — repositories, agent transcripts, generated artifacts, metadata — is stored on encrypted-at-rest infrastructure provided by our cloud host.

No model training on customer data

Zerg does not train models on customer code, prompts, agent transcripts, or runtime data. Customer data is used to operate the service for that customer and nothing else.

No card data on our systems

Customer payment processing routes through Stripe. Zerg does not store cardholder data and PCI DSS scope does not apply to us directly.

What is not yet

Current limits.

We do not currently hold SOC 2, ISO 27001, or any other third-party security certification. We do not have a HIPAA BAA available, and we are not a HIPAA Business Associate. We do not offer customer-managed encryption keys, single-tenant dedicated instances, or BYOC / VPC deployment.

If your project needs one of these capabilities, discuss it with our team before choosing a deployment.

Regulated industries

Talk to us before you buy.

If you are evaluating Zerg from a healthcare, financial services, public sector, or other regulated context, please reach out before opening procurement. We will tell you what we can and cannot support today, and where we expect to be in the next few quarters.

We can review your requirements and provide the information your security team needs to evaluate the fit.

security@zergai.com

Get started

Try the product. Ask us anything.

Try Zerg Cloud