ZERVYX TRUST CENTER
Security
Last updated: August 14, 2026
Zervyx is designed around least privilege, organizational data isolation, encrypted transport, and accountable access.
Current controls
- HTTPS/TLS encryption for browser and API traffic.
- Server-side authentication checks for protected application pages and API routes.
- Organization-scoped database queries and ownership validation.
- Owner and Admin manage brands and integrations; Analyst and Viewer are read-only.
- Amazon secrets and OAuth refresh tokens are never stored in browser storage or committed to source code.
Credential handling
Production credentials are stored in managed secret storage and accessed by server-side code. Amazon refresh tokens are encrypted before persistence.
Incident response
Zervyx investigates and contains suspected unauthorized access, preserves relevant evidence, notifies affected parties where required, and reports incidents involving Amazon Information within the applicable timeframe.
Report a concern
Send reports to stels9377@gmail.com. Do not include passwords or API secrets.