Your API keys are encrypted with AES-256-GCM before storage. Zero AI staff cannot read, access, or transmit your keys. Decryption occurs only client-side in your browser. We never see your keys — this is enforced by design, not policy.
The Bring Your Own Keys (BYOK) vault uses client-side encryption exclusively:
When you click “Test Key” in the vault, your key is sent directly from your browser to the provider’s API (e.g., api.openai.com). Zero AI’s servers are not in the data path. The test result (pass/fail) is returned; the key itself is never logged or stored by our infrastructure.
If you discover a security vulnerability in Zero AI, please report it responsibly:
We acknowledge all reports within 24 hours and aim to patch critical issues within 72 hours. We do not pursue legal action against good-faith researchers.