Security
Built so no one — including us — needs your data to trust you.
ZTZK is designed around one rule: prove the fact, keep the record. Here is how that shapes the way we handle your data.
Design principles
How ZTZK handles your data.
- Your data stays in your systems
- Checks run inside your own infrastructure. Signed results and proofs leave; the records behind them don’t.
- Proofs, not records
- Where a fact involves sensitive data, it’s proven with a zero-knowledge proof rather than disclosed — to us or to anyone else.
- Post-quantum signatures
- Every result is signed with ML-DSA-65, the NIST-standardized post-quantum signature scheme, so the record stays trustworthy as cryptography changes.
- No trust in ZTZK required
- Verification uses published public keys. Your auditor, bank or customer can check a result without access to ZTZK — and it stays checkable even if we’re not in the picture.
- Nothing changes quietly
- Rules are versioned and fingerprinted, and results live in an append-only ledger — so neither a rule nor a result can be edited after the fact without it showing.
Report a vulnerability
Found something? Tell us.
Email [email protected] with a description of the issue, the steps to reproduce it and any proof of concept. Please give us a reasonable chance to fix it before disclosing it publicly. We won’t pursue good-faith research that avoids harm to our users and their data.
This website collects only what you give us when you request access. See our privacy policy.
Request access
Evaluating ZTZK for your security team?
Request a walkthrough of our architecture and controls, and we'll take your security team through it.
We use your email only to reply to your request. Privacy policy
✓ Request received. We'll be in touch.