Security overview

Zild treats identity, tenant segregation, encryption, secret protection, abuse prevention, data minimization, observability, and audit as platform-wide controls.

Zild treats identity, tenant segregation, encryption, secret protection, abuse prevention, data minimization, observability, and audit as platform-wide controls.

Security principles

  • Least privilege and need-to-know access for users, services, agents, and integrations.
  • Logical tenant segregation and consistent backend authorization for every protected operation.
  • Encryption in transit and at rest, with credentials and secrets kept outside application content.
  • Input validation, request limits, anomaly monitoring, audit trails, and operational guardrails.

Defense across the flow

Security controls apply before, during, and after an agent action. Zild validates identity and permission scope, limits the context sent to external services, protects sensitive output, records relevant events, and supports investigation without placing unnecessary confidential data in logs.

Abuse and leakage controls

Operations can be limited by user, tenant, channel, or integration. The platform validates inputs, detects unusual patterns, masks sensitive values when needed, restricts histories and reports by scope, and can block or slow anomalous use.