Security & Trust

What we touch, what we store, and what we honestly don't do.

We build privacy-first tools, which means we owe you a straight answer about how each product handles your data. No marketing layer, no certification badges we don't hold — just the truth, organized by product.

Core principles

How we think about your data across every product.

Minimum necessary access

Each product asks for the least access it needs to do its job. Read-only where read-only is enough. No requests for power we'd never use.

Purpose-limited use

Data we receive is processed for the stated purpose only — fraud detection, masking, audit logging. We don't sell it, share it with advertisers, or use it for unrelated features.

Honest about limits

We don't claim certifications we don't hold. We don't say "bank-grade" or "military-grade." If we run on certified infrastructure, we say so. If we don't, we say that too.

PayGuard · For business

How PayGuard handles your AP data.

PayGuard connects to Microsoft 365 and QuickBooks with read-only access to detect invoice fraud. Here's exactly what that means.

What PayGuard does
  • Reads invoice emails and attachments from Microsoft 365 via read-only OAuth scopes (Mail.Read).
  • Reads vendor records and historical payment data from QuickBooks via read-only OAuth.
  • Stores invoice metadata, OCR text, and fraud signals encrypted at rest on AWS infrastructure (US-East).
  • Maintains an audit log (ProofTrail) of every detection and team action for your records.
  • Deletes your tenant data within 90 days of cancellation. (Anonymous vendor-fraud signals stay in our network intelligence layer.)
What PayGuard doesn't do
  • Never sends, deletes, or modifies any email in your inbox.
  • Never moves, holds, blocks, or reverses funds. Detection only.
  • Never reads non-invoice email. Our pipeline filters out everything that isn't AP-related before processing.
  • Never sells your data, shares it with advertisers, or uses it to train models for unrelated products.
  • Never silently scans your inbox when your trial or subscription is inactive. Hard rule, enforced at the worker level.
An honest note on SOC 2 PayGuard runs on AWS, which holds SOC 2 Type II certification for the underlying infrastructure. Zabcore itself is not SOC 2 certified. If your procurement team requires a SOC 2 report from us specifically, we're not the right vendor yet. We'll publish a status when that changes.
AI Leak Guard · Free, open source

How AI Leak Guard handles your data: it doesn't.

AI Leak Guard runs entirely in your browser. Nothing you type, paste, or mask ever leaves your device. This is the architectural promise, not a marketing claim — the code is open source on GitHub and you can verify it.

What AI Leak Guard does
  • Runs detection regex locally in your browser when you paste content into a supported AI tool.
  • Replaces detected sensitive data with placeholders before the AI tool receives the text.
  • Once per day, downloads updated detection patterns from a static CDN (one-way fetch, no upload).
  • Increments a local counter you can see in the popup. The counter stays on your device.
What AI Leak Guard doesn't do
  • No backend server. There is nowhere for your data to be sent.
  • No analytics, no telemetry, no error tracking, no usage logs.
  • No account, no email, no registration. We don't know who installed it.
  • No reading of pages other than the AI tools you've explicitly enabled (ChatGPT, Claude, Gemini, Perplexity, Copilot).
  • No access to browsing history, cookies, saved passwords, or autofill data.
Infrastructure

Where things run, and who runs them.

PayGuard is hosted on AWS. AI Leak Guard runs entirely on your device. Both products use only the infrastructure they need.

AWS US-East
PayGuard hosting
TLS 1.2+
Encryption in transit
AES-256
Encryption at rest
Your device
AI Leak Guard runs here
Responsible disclosure

Found a security issue? Tell us first.

If you've found a vulnerability in PayGuard or AI Leak Guard, we want to hear about it before anyone else does. We don't have a formal bug bounty program yet, but we take every report seriously and will credit researchers publicly (with permission) on resolution.

Please don't share findings publicly until we've had a reasonable window to fix the issue — typically 30 days for critical issues, 60 days for everything else.

support@zabcore.com