ZeroDelay← Back to home

Security

Last updated: September 11, 2026

🔒TLS encryption in transit
🗄️Encrypted at rest
🔑Managed auth via Clerk
💳PCI-DSS payments via Stripe

Encryption

All data transmitted between your browser and ZeroDelay.ai servers is encrypted using TLS. We enforce HTTPS-only connections and set HSTS headers (Strict-Transport-Security) to prevent protocol downgrade attacks.

Data at rest — including your business profile, coaching plans, and check-in history — is stored using controls provided by Replit and other cloud infrastructure providers. Encryption and other controls may vary by service.

Authentication

ZeroDelay.ai uses Clerk, a dedicated authentication platform, to manage all user accounts and sessions. Passwords are never stored on our servers — Clerk handles credential storage, hashing, and session management on our behalf.

Sessions are validated on every authenticated request via Clerk's signed session tokens. Clerk supports two-factor authentication (TOTP and email OTP) for users who wish to enable it.

Infrastructure

ZeroDelay.ai uses Replit and other cloud infrastructure providers for hosting and storage. These providers supply infrastructure and security controls that may change over time; no security measure eliminates all risk.

Database access is restricted to the application layer. Direct database connections from the public internet are not permitted.

We review dependencies periodically for known vulnerabilities and address critical issues as they are identified.

Third-Party Processors

Payment card data is handled exclusively by Stripe, a PCI-DSS Level 1 certified processor. ZeroDelay.ai never processes, stores, or transmits raw card numbers.

AI inference is performed via Anthropic's API (accessed through Replit's managed AI integration) over encrypted connections. Under Anthropic's API data processing terms, customer data submitted via API is not used to train models.

Transactional email is delivered via Resend. Email content may include your first name and plan summary; no financial data is included in emails.

Access Controls

Production database access is restricted to authorised engineering staff through our internal admin console.

We follow the principle of least privilege: access is granted only as required.

Key user and payment events in the ZeroDelay.ai platform are logged with timestamps for operational monitoring.

Data Isolation

Each user's data is isolated at the application layer using authenticated session tokens. Users cannot access other users' plans, check-ins, or profile information.

Shared plan links use cryptographically random tokens (not sequential IDs) to prevent enumeration attacks.

Incident Response

No method of transmission or storage is completely secure. If we identify a security incident requiring notice under applicable law, we will provide notice as required by that law.

Responsible Disclosure

Found a security vulnerability? We appreciate responsible disclosure and will work with you to resolve it promptly. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.

zerodelay.ai.cs@hypersolutionsconsulting.com →