Back home

Trust + safety

Security posture.

Draft · under legal reviewLast updated · June 2026

This page summarises how SubZero handles your data. It is a plain-English companion to the Privacy Policy, Terms, and DPA.

Transport security

Public SubZero services use HTTPS. Managed infrastructure providers apply their standard storage protections. SubZero does not currently claim end-to-end encryption or customer-managed encryption keys.

Bank access

Optional bank linking is handled by the connector provider. Login credentials are entered into the provider's interface rather than SubZero. Connector availability and region coverage are shown before setup.

SubZero does not currently operate an Account Aggregator integration in India. Manual entry and supported CSV import are the launch-ready alternatives.

Email access

Gmail is a limited beta until its public OAuth configuration is approved. When enabled, SubZero requests scoped OAuth permissions and documents the data used by the connector.

Current assurance status

  • SubZero has not completed a SOC 2 audit.
  • SubZero has not completed a formal GDPR or DPDP assessment.
  • Draft legal pages are not certifications.

Account deletion

Export, deletion, and retention enforcement are launch-readiness work. The final policy will state verified retention windows when those controls are production-ready.

Disclosures

Found a security issue? Email security@subzero.app. Reports are reviewed before any public disclosure.