Security

Secure by design, from the runtime up.

ZyroStack isolates project data, separates the control plane, and encrypts everything by default.

Security & isolation

Built secure, from the runtime up.

ZyroStack separates your public API from your control API, isolates project data, and encrypts everything by default — so you can ship to production with confidence.

Read about security →

Isolated runtimes

Shared, isolated, or dedicated runtime modes keep every project’s data separated.

Separated control plane

The public API and the control API run on different surfaces and domains.

Encrypted everywhere

TLS in transit, encryption at rest, and automatic SSL on every domain.

Audit logs

Every admin and deployment action is recorded and searchable.

Public vs control API separation

Your public API and control API run on different domains and surfaces so admin access is never exposed publicly.

Runtime isolation modes

Choose shared, isolated, or dedicated runtimes depending on the sensitivity of your workload.

Secrets management

Environment secrets are encrypted and scoped per environment — development, preview, staging, production.

Least-privilege roles

Granular roles and permissions for both your app users and your team members.

SOC 2 (in progress)GDPR-readyData residencyEncryption at restTLS 1.3Audit logging

Build and launch production apps with AI.

Every project gets a frontend, backend, API, auth, database, control panel, custom domains, and staging-to-production deployment — all in one platform.