Trust & security

Specific controls. Honest boundaries.

Zero Trust Security treats trust as an engineering outcome. This page separates implemented safeguards from work that is still being qualified.

Implemented today

Public-site and product foundations already in use.

Website security
Strict transport security, restrictive browser policy headers, same-origin form handling, bounded input, and a fail-closed intake configuration are implemented.
Data minimization
The public sites use no advertising trackers or marketing pixels. Inquiry forms request only routing and contact information and explicitly reject sensitive infrastructure data.
Authentication direction
OZVO's qualified local product work uses authenticated sessions, MFA, tenant and site boundaries, least privilege, and explicit authorization inputs.
Local-first resilience
OZVO is designed so temporary loss of Cloud connectivity does not deliberately disable essential local security or customer evidence.

Pilot qualification

Controlled, evidence-led maturity.

OZVO capabilities move through local and disposable-lab qualification, security review, repeatable packaging, and explicit release gates. Pilot status is not general availability.

Production targets

Hardware-backed and cloud trust.

TPM-backed keys, Secure Boot, full-disk encryption, Cloud PKI, remote fleet management, and broader support workflows remain production targets until separately qualified.

Responsible disclosure

A monitored security contact is being prepared.

We will publish a formal disclosure policy and security.txt only after the receiving mailbox is verified and monitored. No active public vulnerability-reporting address is claimed today.

Do not send credentials, exploit payloads, customer data, or sensitive infrastructure details through the sales form. For ordinary service or product questions, use Contact.