At Zekro Security, privacy and operational security are our product. We do not sell your data and we do not expose information collected during security audits.
Our platform operates under the principle of "Demonstrate, do not just Alert". To validate the existence of critical vulnerabilities, the Zekro engine will extract controlled data fragments (Proof of Exploitation) from your infrastructure. Regarding this data:
Once the vulnerability has been demonstrated and the Client has evaluated the report, we proceed to the cryptographic deletion of any extracted data. If the Client opts for our Continuous Managed Defense services, operational logs are kept in isolated silos, but raw exploitation data is always destroyed.
We strictly collect the necessary information to manage the B2B service and guarantee the traceability of offensive actions due to legal requirements:
The public platform (zekro.io) uses strictly essential cookies to maintain secure sessions in the client portal (ephemeral session tokens) and to protect infrastructure against abuse (identifying malicious agents attempting to attack Zekro).
All Zekro infrastructure operates in facilities with enterprise security protocols aligned with international standards. Any data transfer is governed under reinforced confidentiality protocols.
For requests regarding data protection and regulatory compliance: security@zekro.io