Security at Zyvela
How we think about protecting your data and keeping intelligence accountable.
These are our current principles and practices — described in general terms, and evolving as we grow.
Workspace isolation
Data and context are scoped to a workspace, so information stays where it belongs.
Human-in-the-loop
Consequential actions and memory are designed to be reviewed by a person, not left fully autonomous.
Controlled access
Access to data and capabilities is scoped to its purpose, with permissions in mind by default.
Auditability (roadmap)
We are building toward traceable, reviewable action history so activity can be inspected over time.
Safe automation
Automations are designed to run within guardrails, with approvals for actions that carry weight.
Data minimization
We aim to collect and retain only what is reasonably needed to deliver the product.
Zyvela is an early-stage platform, and we're intentionally careful about what we claim. The items above describe how we approach security today and where we're heading — they are practices and principles, not certifications. We do not currently claim any formal compliance certifications.
If you have a specific security question, a responsible-disclosure report, or requirements you need to discuss, please reach out to hello@zyvela.app and we'll respond.