Trust by design
Security approach
Public website
The public site is intentionally low-data. It does not accept file uploads, process payments or store fit-check submissions. The contact form opens a draft in the visitor’s own email application.
Public ZEUS
Public ZEUS is separated from the private ZEUS command system. It uses approved public information only and cannot access Growth OS workspaces, client files, provider connections or private memory. The endpoint enforces an origin allowlist, input limits, privacy-preserving server-side rate limits, a daily AI allowance and no model tools. AI requests use conversation storage disabled.
Growth OS and provider connections
Growth OS is a separate application. Client-beta ZEUS uses a separate prompt, memory and limited draft-only tools. Connections use provider authorisation, protected server credentials and server-side verification. A “connected” label should appear only after the relevant callback and asset checks succeed.
Operational principles
- Client accounts and provider relationships remain client-owned.
- Secrets must be stored in protected server configuration, never source control or page content.
- Access should be least-privilege, role-aware and revoked when no longer needed.
- Material publishing, spending and account changes should remain approval-led.
- Dependencies, redirects, headers and important journeys should be tested before release.
Responsible reporting
If you believe a Zarak-managed service has a security issue, email lenin@zarakmarketing.com with the affected URL, a clear description and safe reproduction detail. Do not access, change or disclose another person’s information.
Limits
No internet service can promise absolute security. Security controls must be reviewed against the actual deployed application, providers and data flows. This page does not claim independent certification or complete immunity from risk.