Security practices, in plain language.

No compliance theater, no badges we haven't earned. This page describes what we actually do to protect the platform and your data.

What data ZeroBot processes

To classify traffic, ZeroBot processes the request metadata your integration sends us: IP address, user agent, and the fingerprint/behavior signals collected by the JavaScript challenge. That data is used for detection and for your traffic logs — nothing else.

  • No advertising trackers, no data resale, no profiling beyond bot classification.
  • Cross-client threat intelligence shares only anonymized IP reputation scores — never visitor identity or customer data.
  • Details of processing terms are in our Data Processing Agreement and Privacy Policy.

Platform security

  • All traffic to zerobot.info and its APIs is served over HTTPS; plain-HTTP requests are permanently redirected.
  • Baseline security headers (HSTS, nosniff, frame protection, referrer policy) are sent on every response.
  • Third-party API credentials stored by the platform are encrypted at rest.
  • Admin surfaces are separated from customer surfaces, protected with one-time-password authentication.
  • Payments are processed by established providers — card details never touch our servers.

Reliability & recovery

  • Current and historical availability is public on our status page.
  • The detection API is designed to fail open by default: if ZeroBot is ever unreachable, your visitors get through and the incident is logged. Your site's availability is never hostage to ours.
  • Databases are backed up on an automated twice-daily schedule with tested restore procedures.

Responsible disclosure

If you believe you've found a security vulnerability in ZeroBot, we want to hear about it.

  • Contact details are published at /.well-known/security.txt (RFC 9116).
  • Report privately to support@zerobot.info — we read every report and will respond to you directly.
  • We ask for reasonable time to fix before public disclosure, and we won't take action against good-faith research.

The false-positive promise

Blocking a real visitor is the worst thing an anti-bot product can do. We engineer every detection layer with safeguards for residential and mobile traffic, and we treat every confirmed false positive as a critical bug — investigated ahead of feature work. If a ZeroBot-protected site wrongly blocked you, tell us.

What we don't claim

We don't currently hold SOC 2 or ISO 27001 certification, and you won't find those badges here until we do. What you will find is honest engineering, a public status page, published security contact details, and support answered by the people who build the product.