Skip to content

Legal

Security

How we protect client data, our infrastructure and the products we ship.

Our approach

Security is built into delivery — not bolted on before launch. Every engagement includes access controls, secrets management, dependency scanning and audit logging appropriate to the product's risk profile.

Client data

  • Encryption in transit (TLS 1.2+) and at rest where applicable
  • Role-based access with least-privilege defaults
  • No production data on local machines without approval
  • NDA and MSA confidentiality on every engagement

Infrastructure

We deploy to established cloud providers (AWS, Vercel, Cloudflare, Fly.io) with infrastructure as code, automated backups and monitored alerting. Credentials are stored in team vaults — never in repositories.

Compliance support

We support HIPAA, SOC 2 and GDPR requirements as part of client engagements — built into delivery from week one. Talk to us about your regulatory context on a discovery call.

Report a vulnerability

If you believe you've found a security issue on znn.agency or in our open-source work, email hello@znn.agency with subject line "Security". We aim to acknowledge reports within two business days.