Trust & Security
Built for developers who read the security page first.
Security is a first-class concern at Zapinner. Below is exactly how we protect your account, your keys, and your data — in plain language, described honestly, with no claims we can't back up.
How we protect your data
Encrypted in transit and at rest
Every request to Zapinner is served over HTTPS/TLS. Data is stored with a managed database provider that encrypts data at rest. Secrets and keys are stored encrypted, never in plaintext.
Scoped, rotatable API keys
Each account gets its own API keys. Every request is authenticated and scoped to the issuing account. Rotate or revoke a key instantly from the dashboard — revocation takes effect immediately.
Strict tenant isolation
Every request is bound to the authenticated account, and all data access is filtered by that account's identifier. One customer's key can never read, write, or meter another customer's data. This boundary is covered by automated tests in our release checks.
Hashed passwords, managed sessions
Dashboard access runs through a managed authentication provider with hashed passwords and short-lived sessions. We never see or store plaintext passwords.
Payments handled by Stripe
Billing is processed by Stripe. Full card numbers never touch our servers — we store only the non-sensitive references Stripe returns for display and reconciliation.
Validation, rate limits, and metering
API inputs are validated before processing, requests are rate-limited per key, and usage is metered so anomalous activity is detectable and limits are enforced consistently for everyone.
Who processes your data
We share data only with the service providers that run Zapinner, each under its own security commitments. We do not sell your data, and we do not use the content of your API requests to train models for other customers.
| Provider | Purpose | Data processed |
|---|---|---|
| Vercel | Application hosting and edge delivery | Request routing, logs |
| Supabase | Authentication and primary database | Account, session, app data |
| Stripe | Payments and billing | Billing details, card tokens |
| Resend | Transactional email delivery | Email address, message content |
Responsible disclosure
If you believe you've found a security vulnerability, email security@zapinner.com with details and reproduction steps. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and never access or modify data that isn't yours. We appreciate and credit researchers who report responsibly.
Compliance posture, stated honestly
We build to strong security practices, but we do not currently claim any formal certification such as SOC 2, ISO 27001, HIPAA, or PCI Level 1. If your use case requires a specific certification or a Data Processing Agreement (DPA), email security@zapinner.com and we'll work through your requirements. We would rather be straight with you than overstate our posture.
Start with 1,000 free
No credit card required. Scoped keys, instant revocation, and usage you can see from day one.
This page describes Zapinner's current practices for transparency and does not constitute legal advice. Effective September 7, 2026. Questions? support@zapinner.com.
