Hosting and data residency
The website and (when operational) the hosted inference API are hosted exclusively on EU-region infrastructure. We do not store customer inference data; predictions are returned and the request payload is dropped from memory immediately. Diagnostic logs (no payload contents) are retained for 7 days.
Sub-processors
For hosted services, our sub-processors are limited to (a) the EU-region cloud provider running the inference compute, and (b) email infrastructure for transactional messages. A current sub-processor list is available on request via security@zerooneresearch.ai.
Open-weight deployment
For customers who require zero data egress: we ship the model weights under Apache-2.0. Run inference fully inside your own VPC. We never see your data.
Responsible disclosure
To report a security vulnerability: security@zerooneresearch.ai with subject line “Security disclosure”. We acknowledge reports within 5 business days. We do not currently run a paid bug-bounty program; coordinated disclosure with public credit is offered.
Launch-day placeholder. SOC 2 / ISO 27001 timeline will be published when paid hosted services launch.