Security at Zeryvo
Local-first design, hardened Kids Lock and responsible vulnerability reporting.
Local-first
The beta is designed without a Zeryvo cloud backend for feed content. Network-related Android permissions are deliberately restricted in the current release configuration.
Kids Lock PIN
PIN verification uses Android Keystore-backed cryptographic material, lockouts for repeated failed attempts and app-level mutation guards.
Data minimisation
Raw captions are not intended to be retained in normal operation. Diagnostic retention is configurable and debug caption retention is off by default.
Report a vulnerability
If you believe you found a security or privacy vulnerability, email security@zeryvo.app. Please include the app version, Android version, device model, steps to reproduce and the expected/actual behaviour. Do not send private third-party feed content unless it is necessary and you are authorised to share it.
What we ask researchers not to do
- Do not access another person’s device or account without permission.
- Do not perform destructive testing against third-party platforms.
- Do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and mitigate it.
Scope statement
This page describes the current beta’s security approach. It is not a certification and does not guarantee that the app is vulnerability-free.
