Trust + safety
Security posture.
This page summarises how SubZero handles your data. It is a plain-English companion to the Privacy Policy, Terms, and DPA.
Transport security
Public SubZero services use HTTPS. Managed infrastructure providers apply their standard storage protections. SubZero does not currently claim end-to-end encryption or customer-managed encryption keys.
Bank access
Optional bank linking is handled by the connector provider. Login credentials are entered into the provider's interface rather than SubZero. Connector availability and region coverage are shown before setup.
SubZero does not currently operate an Account Aggregator integration in India. Manual entry and supported CSV import are the launch-ready alternatives.
Email access
Gmail is a limited beta until its public OAuth configuration is approved. When enabled, SubZero requests scoped OAuth permissions and documents the data used by the connector.
Current assurance status
- SubZero has not completed a SOC 2 audit.
- SubZero has not completed a formal GDPR or DPDP assessment.
- Draft legal pages are not certifications.
Account deletion
Export, deletion, and retention enforcement are launch-readiness work. The final policy will state verified retention windows when those controls are production-ready.
Disclosures
Found a security issue? Email security@subzero.app. Reports are reviewed before any public disclosure.