Security & control

Your voice and your knowledge, treated like the assets they are.

Zsper is built so the most sensitive thing it holds — your thinking — never moves without your say-so. Here’s exactly how.

Principles

Control by construction, not by policy.

These aren’t promises bolted on after the fact — they’re how the product is wired. The safe path is the only path.

  • You are always in control

    There is no auto-publish path. Every draft, every learned opinion, every retired belief waits for your explicit approval. Nothing that speaks in your voice ships without a human yes.

  • Your data stays yours

    Your brain is your asset — for many founders, it's years of hard-earned market knowledge. It’s never sold, never used to train shared models, and always exportable. Delete a record — or your whole workspace — and it’s gone.

  • Secrets are encrypted

    Bring-your-own-key credentials are encrypted at rest with AES-256-GCM. We never log or expose a raw key. Sessions are HMAC-signed cookies — a raw user id is never trusted.

  • External access is least-privilege

    MCP connectors are scoped to a single workspace. Anything a chat saves lands pending your review — never published, never trusted automatically, and nothing you made in the app can be edited or deleted from outside. No cross-workspace access, and suppressed or proposed records stay hidden. Revoke any token instantly.

acme-studioSecurity posture

Guarantees

No auto-publishEnforced
Human approval gateOn every stance
Keys at restAES-256-GCM
SessionsHMAC-signed
MCP accessRead-only · scoped
Data exportYours, anytime

At a glance

The controls, in one table.

Publishing

No auto-publish; human approval gate on every stance

Authentication

Google OAuth; HMAC-signed sessions verified server-side

Secrets

BYOK keys encrypted with AES-256-GCM at rest

External access

MCP is review-gated, workspace-scoped, and revocable

Isolation

Per-workspace brains — voices never cross-contaminate

Data ownership

Exportable and deletable; never used to train shared models

AI grounding

Drafts can’t invent facts, names, dates, or quotes

Fair use

Metered usage with caps; ownership re-checked on every action

Building toward SOC 2, DPDP-ready data practices, and a formal DPA for larger teams. Talk to us about enterprise requirements before you sign anything.

FAQ

Questions, answered.

Is my writing used to train AI models?+

No. Your knowledge and drafts ground your own generations — they are never used to train models, ours or anyone's.

Can Zsper publish or delete anything on its own?+

No. There is no auto-publish anywhere in the product, and knowledge is suppressed and traced rather than deleted — every destructive-looking action waits for a human.

Can I export my data?+

Yes — your articles, your brain, and your settings are yours to inspect and export at any time, trial or paid.

Where do BYOK keys live?+

Encrypted at rest with AES-256-GCM. The raw key is never logged and never shown again after you save it, and you can remove it anytime.

More questions? Visit the Help Center

Speed with accountability — not one or the other.

Everything that speaks in your voice waits for your explicit yes.

14-day free trial · No credit card required