ZERO

Privacy Policy

Last updated August 22, 2026

This policy explains what information Zero collects, why we use it, and the choices available to you when you use our website, APIs, dashboard, agents, and integrations.

This Privacy Policy ("Policy") describes how Zero ("Zero," "we," "our," or "us") collects, uses, and discloses personal information from users of our websites (the "Site"), security-data catalog, dashboard, REST API, Model Context Protocol (MCP) server, agents, integrations, and related services (collectively, the "Services"). By using the Services, you acknowledge the practices described in this Policy.

What information we collect and maintain about you

We collect personal and other information directly when you provide it through the Services. We may also automatically collect information about you and your device when you access or interact with the Services.

Personal information collected through the Platform.

If you create an account or use the Platform, we may process your Google account identity, including your name, email address, profile image, and provider account identifier; organization name and membership; invitations and roles; session, authentication, and security-event information; API key metadata and API usage; billing and plan information; agent settings; software watchlists; alert and run history; and integration settings such as a Slack channel and encrypted Slack incoming webhook. API keys are stored as cryptographic hashes after creation, and configured integration secrets are encrypted at rest.

Personal information collected through the Site.

You may browse the public Site and security catalog without creating an account. If you contact us, request support, join a waitlist, create an account, or use another interactive feature, we collect the information you submit, such as your name, business email address, organization, and message.

Prompts and Outputs.

The Services may allow you to submit queries, prompts, source code excerpts, software inventory, configuration, documents, or other materials (collectively, "Prompts") through the dashboard, REST API, MCP server, agents, or integrations. The Services may generate search results, findings, alerts, summaries, recommendations, or other responses based on those Prompts (collectively, "Outputs"). If Prompts contain personal information, we collect that information and it may be reproduced in Outputs. Do not submit information that you are not authorized to provide.

Careers.

If you apply for a role with us, we may collect contact details, a resume, employment and education history, work samples, references, and other information you choose to provide. If you apply through a third-party recruiting service, we receive information made available to us by that service.

Web log data.

When you use the Services, we automatically receive and record information such as IP address, requested URLs, referring pages, date and time, response status, API operation, API key identifier, rate-limit and usage counts, browser and operating-system attributes, device identifiers, general geographic location, authentication events, and diagnostic logs. We use this information to operate, secure, troubleshoot, and measure the Services.

Cookies.

We use cookies and similar browser storage to authenticate users, maintain sessions, remember interface preferences, prevent abuse, and support essential Site functionality. You can configure your browser to refuse or delete cookies, but some authenticated or personalized features may not function correctly.

Web beacons.

Our Site or service communications may use small electronic files, sometimes called web beacons or pixels, to determine whether a page or message was viewed and to measure delivery or engagement. We use this information to operate communications and improve reliability, not to sell personal information.

SDKs and mobile advertising IDs.

The Services may use software development kits and similar technologies from service providers for authentication, error monitoring, security, and performance. Zero does not currently operate a consumer mobile application or use mobile advertising identifiers for targeted advertising.

Third-party plugins.

The Services may include integrations or links from providers such as Google and Slack. When you enable an integration, information may be exchanged with that provider at your direction. The provider's use of information is governed by its own terms and privacy policy.

Third-party online tracking and behavioral advertising.

Zero does not currently use personal information collected through the Services for cross-context behavioral advertising and does not sell personal information for money. If our practices change, we will update this Policy and provide any choices required by law.

Aggregated and deidentified information.

We may derive aggregated or deidentified information from use of the Services, such as overall API traffic, feature adoption, source freshness, agent performance, and service reliability. We maintain such information in deidentified form and do not attempt to reidentify it except as permitted by law to test deidentification methods.

How We Use Your Information

We use information to provide, maintain, secure, and improve the Services; authenticate users and enforce organization permissions; issue and manage API access; answer search and MCP requests; run configured agents; match software watchlists against security intelligence; deliver alerts to destinations such as Slack; process subscriptions and usage; enforce rate limits; diagnose errors; prevent fraud and abuse; communicate about accounts, security, support, products, and policies; comply with law; and protect Zero, our users, and others.

We do not use Customer Data to train a third-party general-purpose large language model unless Customer expressly directs us to use a provider whose applicable terms permit that processing. We may use deidentified Usage Data to evaluate and improve service quality.

With Whom and Why We Disclose Your Information

Partners and Affiliates.

We may disclose information to corporate affiliates and business partners that help operate or support the Services, subject to protections consistent with this Policy.

With our customers.

If you use the Services through an organization, its administrators and authorized members may access your account identity, membership, API usage, agent configuration, alerts, and other organization activity. The organization controls its own use of that information.

Third-party service providers.

We disclose information to vendors that provide cloud hosting, databases, authentication, logging, monitoring, email, payment, customer support, security, and artificial-intelligence infrastructure. They may process information only to perform services for us or as otherwise permitted by their agreements and law.

Other third parties and integrations.

At your direction, we disclose information to integrations you configure. For example, zero/alert may send an incident notification, affected-software match, and related security context to a destination selected by your organization.

Analytics.

We may use service providers to understand aggregate traffic, performance, and feature use. We do not authorize providers to use Customer Data for their own advertising.

Interest-based Advertising.

We do not currently disclose personal information to advertising networks for interest-based advertising. We may conduct contextual business marketing that does not rely on cross-site tracking.

Legal purposes.

We may disclose information to comply with law, legal process, or government requests; enforce agreements; investigate abuse or security incidents; protect rights, property, safety, or service integrity; or support a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.

Aggregated information.

We may disclose aggregated or deidentified information that does not reasonably identify an individual or Customer, including reports about security-data coverage, API use, and service performance.

Consent.

We may disclose information for another purpose after providing notice and obtaining consent where required.

Public and Third-Party Security Data

Zero collects and organizes public and licensed security information from publishers and other sources, including CVEs, CWEs, advisories, attack patterns, affected software, scoring data, exploitation evidence, remediation information, source records, and provenance. This catalog information is distinct from Customer Data and remains subject to the applicable publisher's rights, notices, licenses, and terms.

Your Choices

You may update account and organization settings, revoke API keys, remove integrations, change agent watchlists, and manage communications where those controls are available. You may request access to, correction of, portability of, or deletion of personal information by contacting us. We may verify your identity and retain information where required for security, legal compliance, dispute resolution, or legitimate records.

Depending on where you live, you may also object to or restrict processing, withdraw consent, or appeal a decision. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising applicable privacy rights.

External Links

The Services link to security publishers, repositories, advisories, documentation, and other third-party sites. We do not control those sites, and this Policy does not apply to their privacy practices.

Data Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption for configured integration credentials, cryptographic hashing of API keys, service logging, and separation between global catalog data and organization-scoped control data. No method of transmission or storage is completely secure.

You are responsible for safeguarding login credentials, API keys, integration secrets, and devices used to access the Services. Notify us promptly if you believe an account or credential has been compromised.

Data Retention

We retain personal information as needed to provide the Services, maintain business and security records, comply with law, resolve disputes, and enforce agreements. Public security records and provenance may be retained historically to preserve source history and explain how catalog values changed.

International Users

The Services may be operated from and information may be processed in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards for international transfers.

Children

The Services are intended for business and professional use and are not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes to this Policy

We may update this Policy to reflect changes to the Services, our practices, or law. We will post the updated Policy and revise the date above, with additional notice for material changes where required.

How to Contact Us

Questions, privacy requests, or concerns about this Policy may be sent to support@zdlake.com. Include enough information for us to understand and respond to the request.