Skip to main content

Security and trust

What happens to your data when you work with us, in plain language.

  • Stored in the United StatesOn Google Cloud, and every service we use processes data there too.
  • Encrypted in transit and at restWith an extra layer for integration credentials and API tokens.
  • Never used to train modelsNot ours, and not anyone else's.
  • GDPR, UK GDPR and CCPACovered by our Data Processing Addendum, signed on request.
  • You choose the model providersAn Enterprise workspace limits which ones its flows may use.

Where your content goes

Your team
  • Signs in with your company's identity provider on Enterprise
  • Roles decide who can do what
Encrypted in transit
Your ZeroWidth workspace
  • Stored on Google Cloud in the United States
  • Encrypted at rest, credentials encrypted again
  • Kept apart from every other workspace
Only when you run something
The model you chose
  • Through OpenRouter or a provider you configure
  • Never used to train models
Or keep it all in-houseThe Workbench SDK runs your flows inside your own systems, with your own model keys, so your content never has to reach our workspace at all.

What AI models see

  • We don't train on your content

    ZeroWidth does not use your content to train, fine-tune or improve AI models, ours or anyone else's.

  • Sent only to do what you asked

    Your content goes to a model provider only to run what you've set up, through OpenRouter or a provider you configure yourself. That provider's own terms cover what it does on its side.

  • Choose the models

    An Enterprise workspace can limit which model providers its flows are allowed to use.

  • Or keep it all in-house

    The Workbench SDK runs flows entirely inside your own systems, with your own model keys.

Who can get in, and what they can do

  • Roles

    Owners, admins and members have different permissions, and only an owner can delete a workspace.

  • Single sign-on

    On the Enterprise plan, your team signs in with the identity provider your company already uses. We never see anyone's password.

  • Keys that do only what you allow

    API keys and personal tokens carry only the permissions you give them, product by product, read or write.

  • Nothing changes without approval

    When zv1 wants to change your work, it shows the exact edit and waits for a person to approve it.

Your data stays yours

  • Take it with you

    Flows export as portable files, and Ledger exports its full history as CSV or JSON. If you leave, you have time to export your content afterwards.

  • Deleting removes credentials at once

    When a workspace is deleted, its integration credentials and stored secrets are removed immediately.

Our commitments, in writing

Our Data Processing Addendum covers GDPR, UK GDPR and the CCPA, including the notification duties that come with them. A signed copy is available on request.

Who processes your data

A short list of companies handles hosting, sign-in, email, payments and routing to model providers on our behalf. All of them process data in the United States, and we give notice before adding one.

See the current list →

Read the full documents

Have a question your security team needs answered?

Ask us directly. To report a vulnerability, email security@zerowidth.ai and we'll reply within two business days.

Talk to us