ZV Monogram
ZYVV
OPSEC & ZERO-DATA RETENTION ARCHITECTURE

Privacy Policy

Enterprise CISOs, offensive red teams, and infrastructure engineers require uncompromising operational security. ZYVV is architected from the ground up with strict data minimization, an offline-first workbench philosophy, and a zero-telemetry guarantee.

Effective Date: March 1, 2026•Version: 3.0-SEC•Terms of Service ➔•Refund Policy ➔
The ZYVV Zero-Telemetry & Zero-AI-Training Guarantee

When deploying the Flux Web Security Suite on your workstations, zero intercepted HTTP/S requests, responses, passwords, target scopes, or vulnerability findings are ever uploaded to ZYVV servers. All penetration testing data remains strictly on your local device. Furthermore, we never train, tune, or feed public or proprietary AI models on your code, network traffic, or consulting assessment findings.

01. Our Core Privacy Principles

Data Minimization

We collect only the bare minimum data required to authenticate accounts, process transactions, and issue cryptographically signed offline licenses.

Offline Validation

Flux licenses are validated completely offline using asymmetric Ed25519 digital signatures. Zero phone-home telemetry is required or executed.

Zero AI Model Ingestion

Your source code, architectural schematics, and assessment workpapers are never ingested or used to train external LLMs or neural networks.

02. Information We Collect

We only collect information that you explicitly submit through our web portal or during enterprise service scoping:

  • Account Identity: When registering, we collect your name, email address, optional organization name, and password. Passwords are salted and hashed using industry-standard Argon2id cryptographic algorithms. We never store plaintext passwords.
  • Device Authorization Fingerprint (HWID Hash): To bind Professional and Enterprise licenses to authorized workstations, our desktop client generates a one-way SHA-256 cryptographic hash of non-identifying hardware components. This hash cannot be reverse-engineered to reconstruct physical machine specs or personal identity.
  • Consulting Inquiry & Scoping Records: Information submitted via our Consulting Inquiries Form (organization name, enterprise email, engagement scope, target infrastructure overview, timeline, and compliance objectives) is processed strictly under confidential advisory protocols.
  • Billing & Transaction Metadata: PayPal transaction IDs, subscription tier, payment timestamp, and renewal status. We do not receive, store, or process raw credit card numbers, CVVs, or banking credentials.

03. Information We NEVER Collect or Retain

Local Traffic & Intercepted Flows: All HTTP/HTTPS proxy flows, WebSocket frames, authorization tokens, cookies, fuzzing payloads, and target responses in Flux remain strictly on your local disk inside your SQLite (.flux) project file and Docker sandbox.
Target Domains, IP Addresses & Scopes: We do not log what hosts, microservices, or networks you assess with our desktop tooling.
Permanent Consulting Telemetry: All engagement workpapers, API capture logs, and staging artifacts generated during architecture or penetration testing advisory projects are permanently expunged within 30 days of deliverable acceptance.
Public AI Ingestion: Zero customer source code, architecture diagrams, or security disclosures are shared with third-party AI APIs or LLM model trainers.

04. Payment Processors & Financial Security

All online subscription payments are processed securely through authorized PCI-DSS Level 1 compliant financial gateways:

  • PayPal: Transactions made via PayPal balance or Debit / Credit Card (Visa, Mastercard, American Express) are handled directly through PayPal's tokenized encrypted vault. ZYVV never views or retains payment card details.
  • Invoiced B2B Engagements: Enterprise consulting contracts and annual fleet subscriptions can be billed via direct corporate invoice (ACH / SWIFT Wire) pursuant to a signed Master Services Agreement (MSA).

05. Storage, Encryption & Data Retention Schedules

Portal account data, subscription state, and digital license records are hosted on Neon Serverless PostgreSQL with hardened infrastructure controls:

  • Mandatory TLS 1.3 / SSL encryption in transit across all endpoints and database connections.
  • AES-256 encryption at rest for all stored database records.
  • Argon2id password hashing with individual per-user cryptographic salts.
  • HMAC-SHA256 signature verification on billing webhooks.
Strict Data Retention & Expunction Schedule
Portal User AccountsRetained while account is active. Deleted within 72 hours upon account closure request.
Consulting Assessment ArtifactsAll logs, staging tokens, and workpapers are permanently expunged within 30 days of report delivery.

06. Your Privacy Rights (GDPR & CCPA Compliance)

Regardless of your corporate headquarters or geographic location, ZYVV extends comprehensive statutory privacy protections:

Right to Access & Portability

You may request a machine-readable export of all account profile data and transaction history at any time.

Right to Deletion (“Be Forgotten”)

You may request permanent deletion of your ZYVV account, credentials, and associated machine authorization records.

07. Contact Our Data Protection Team

If you have any questions regarding this Privacy Policy or wish to exercise your statutory data privacy rights, please contact our team:

ZYVV Inc. — Data Protection Office

Email: privacy@zyvv.dev | opsec@zyvv.dev

Security Inquiries: zyvv.dev/contact