Draft — pending legal review. Everything below reflects what's actually implemented today, kept deliberately current rather than aspirational. It has not yet been reviewed by counsel as a formal representation.
Security
Last updated September 2026 · Draft
We'd rather tell you exactly what's true today than make broad claims.
This page lists what's actually implemented, and is equally explicit
about what isn't yet.
In place today
Encrypted camera credentials. RTSP usernames and passwords are encrypted at the field level (AES-256-GCM) before storage and are never returned by any API response.
Hashed API keys. API keys are shown once at creation and stored only as a SHA-256 hash — we cannot retrieve a lost key, only reissue one.
Hashed passwords. Admin, vendor-portal, and customer passwords are hashed with bcrypt; plaintext passwords are never stored.
Tenant isolation. Every vendor-scoped request is checked against that vendor's own data. Cross-tenant access attempts return a not-found response rather than a permission error, so a compromised key can't even confirm another vendor's data exists.
Rate limiting. Login and signup endpoints are throttled to reduce brute-force and abuse risk.
Nightly encrypted-at-rest backups, retained on a 14-day rolling basis, with periodic restore verification.
Per-request session checks. A suspended account loses access on its very next request, not just when its session token naturally expires.
Security headers applied to all responses (via Helmet).
Not in place yet — stated plainly
HTTPS/TLS. This deployment currently runs on HTTP while a domain name and TLS certificate are being finalized. Until that's live, traffic to this specific deployment is not encrypted in transit. We treat this as a priority, not an afterthought.
No formal third-party security audit or penetration test has been conducted yet.
No high-availability / failover infrastructure — the Service currently runs on a single server.
No automated external alerting is active yet. The capability exists (an uptime webhook that can notify Slack/Discord/etc. on status changes) but is not yet configured for this deployment.
Reporting a security issue
If you believe you've found a security issue, please email
info@zennialhub.in with
details. We'll acknowledge reports and work to address confirmed
issues promptly.