Security you can reason about, not just take on faith
Zafronix layers AI onto the systems you already run — cameras, payment processors, venues. That only works if we’re careful with what those systems see and store. Here’s exactly how we handle it, in plain English.
A human is always in the chair
Our AI detects, flags, and drafts — it does not take irreversible action on its own. QORA raises an alert; a person dispatches. VenueFuze drafts the follow-up; an organizer sends it. The consequential decision stays with a human, by design.
Privacy by design
QORA is built to surface events — “a person entered the restricted bay” — not a running feed of identifiable faces. Video is processed on-site rather than shipped wholesale to a cloud. Face recognition, where offered, is default-off, gated behind explicit terms, and always human-confirmed.
We collect the minimum
We ask for what a feature genuinely needs and no more. We do not sell your personal data or share it for cross-context advertising. Where a product processes sensitive footage or attendee records, the default posture is to keep what’s needed for the task — not a permanent dossier.
Your money stays on your rails
VenueFuze is a payment facilitator, not a middleman that holds your funds. Organizers connect their own Stripe, PayPal, or Square account; charges run on their processor and they keep 100% of the ticket price. Zafronix is never the merchant of record for your event.
Encrypted in transit
Every Zafronix site and API is served over HTTPS with modern TLS and HTTP/3, on certificates issued and auto-renewed via Let’s Encrypt. Public servers expose only the ports they need. Bot and abuse protection on our forms runs through Cloudflare Turnstile, with per-IP rate limiting on intake endpoints.
Backed up, off-site, nightly
Production data is backed up on a nightly schedule and replicated off-site to object storage, so an incident on one host isn’t a single point of failure. We keep a documented rebuild runbook so a lost server is a restore, not a catastrophe.
Your data rights, honored
We operate in line with GDPR, UK GDPR, and CCPA. You can request erasure — the “right to be forgotten” — through our self-serve deletion flow, and we act on access and correction requests too. Details, including what each cookie does and how long it lasts, live in our Privacy Policy.
Least privilege, by default
Access to production is limited to what a task requires. Secrets live in restricted, file-permissioned server config — never in the code we ship or in a page a browser can read. Product roles (owner, admin, staff, front-desk) gate who can do what inside each app.
What we don’t claim (yet)
Zafronix is a small, independent studio, and we’d rather be precise than impressive. We are not currently SOC 2, ISO 27001, or HIPAA certified, and we won’t put a badge on this page that we haven’t earned. What you see above is what we actually do today.
If your organization needs a signed security questionnaire, a Data Processing Agreement, or specifics on data residency and sub-processors for a pilot, we’re glad to work through it with you — just ask.
Found a security issue?
We take responsible disclosure seriously and appreciate the researchers who help us. If you’ve found a vulnerability, email us privately — please don’t open a public issue — and give us a reasonable window to fix it before disclosure.