Trust

Security

Exactly what we do — no compliance certifications claimed, no marketing embellishment.

Pre-launch: ZecureRFP is in active development ahead of general availability. The practices below describe our current architecture and are being independently verified — including a two-account data isolation test — before public launch.

Data isolation

Every table that holds account data uses Postgres row-level security, scoped to the owning account. Evaluations, chat history, and share tokens are not readable by other accounts except through a share link you explicitly create.

Uploads

Uploads are validated by file type, file signature, size (40MB), and page count before processing. A document that fails to parse as a real, text-based PDF is rejected rather than silently processed.

Prompt-injection defense

Every language-model call is scoped to only the document excerpts it needs — never the whole document — and any document text is wrapped and explicitly labeled as data, not instructions, before it reaches the model. A separate, deterministic scan also checks the full document for manipulation attempts (e.g. text trying to instruct the system to output a fake score) and flags the finding to you directly rather than silently ignoring it.

Rate limits and quotas

Free accounts are limited to one evaluation; a global daily usage budget acts as a hard kill switch across the whole system to prevent runaway costs or abuse from affecting service for everyone.

Payments

We never touch or store your card details. All payment processing is handled by Dodo Payments; cancellation is a direct in-app action against our own account page, not a hosted billing portal.

Retention

Evaluations are deleted automatically 30 days after creation by default, and sooner on request — see our Privacy Policy.

Model training

We never train models on your documents. Text sent to a language model is used only to answer the specific request it was sent for.

Debug tooling

Internal debug endpoints that expose pipeline execution traces are disabled outside our own development environment and are never reachable in production.

Report a concern

If you find a security issue, please report it to us directly rather than disclosing it publicly — email support@zenexta.com. We take every report seriously.