Trust and security
Who runs ZeroLog, how a workspace is isolated, where the service is hosted, and which outside parties see your data.
Operator and contact
ZeroLog is run by Gian-Luca Luongo, a sole proprietor (natural person) based in Wettingen, Switzerland. Contact for any question, including security reports, is [email protected]. Full legal details are in the Impressum. Vulnerability reports follow security.txt (RFC 9116).
Architecture, from your workspace's side
- Each workspace is its own container, not shared with any other user — see Isolation.
- Outbound traffic from a workspace runs through a filtered network path — see Outbound network.
- A command the AI wants to run waits for your approval first — see Command approval.
- Chats, files and workspace disks are stored on the server in Switzerland; pausing a workspace keeps its disk until you delete it yourself.
Where prompts go
Prompts and the files or images you attach are sent to Featherless, based in the USA, to generate a reply: this is the model inference behind every customer account and is the core of the service. Optional connectors, such as image generation through Leonardo Interactive, only receive data if you switch them on.
Who receives data
| Recipient | Location | Purpose |
|---|---|---|
| Featherless | USA | Model inference |
| Stripe | Ireland and USA | Payment processing |
| Cloudflare | USA; edge location nearest you | Reaching the site, DDoS protection |
| IONOS SE | Germany | Outbound network gateway for containers |
| Microsoft 365 | Ireland | Mail delivery |
| Leonardo Interactive | Australia | Optional image generation, opt-in only |
| USA | Optional sign-in, only if you use it | |
| Anthropic | USA | Automated, redacted error reports |
No data processing agreement or standard contractual clauses with Featherless have been signed yet. Until they are, sending your prompts to the USA rests on the exception for performing your contract (Art. 17 para. 1 lit. b FADP), not on a transfer agreement. The full list, with what each recipient receives and its legal transfer basis under the Swiss FADP, is in the Privacy Policy.
Limits, status and changes
- Compute and credit limits are set per plan — see Plans and Spend limits.
- Live model-provider status is at /status; platform uptime history is on the operator's status page.
- Changes to the service, including security-relevant ones, are announced in the Newsroom.