Security Overview
Zencoder is built for teams that care about code security. Your code is never used for model training, data is encrypted at every layer, and enterprise controls give administrators full visibility.Trust Center
Visit the Zencoder Trust Center for up-to-date certifications, security controls, and compliance documentation.
Data Handling
What Data Does Zencoder Access?
When you use the Coding Agent, Zencoder processes:What Zencoder Does NOT Do
- No model training on your code — Your code is never used to train or fine-tune any AI model
- No code retention — Code context is processed ephemerally unless you explicitly enable persistence
- No cross-customer data sharing — Customer workspaces are logically isolated
- No unauthorized access — Internal access follows least-privilege principles
Encryption
Compliance & Certifications
Zencoder maintains industry-standard certifications:For detailed audit reports and certification documents, visit the Trust Center or contact your account manager.
Enterprise Security Controls
Available on Pro Plus, Pro Max, and Enterprise plans:SSO (Single Sign-On)
Integrate with your identity provider for centralized authentication:- SAML 2.0 and OIDC support
- Enforce SSO-only login for your organization
- Automatic user provisioning and deprovisioning
Audit Logs
Track all significant actions across your organization:- Agent usage and tool invocations
- Configuration changes
- User management actions
- Export logs for compliance and review
Role-Based Access Control
Credit Controls
Admins can set per-user credit caps to prevent any single user from consuming the organization’s shared credit pool. See Team & Admin Controls.BYOK (Bring Your Own Key)
When you use your own API key (OpenAI, Anthropic, Gemini), LLM calls are routed through your key:- Calls go directly to the provider under your API agreement
- No bundled credits are consumed
- Your provider’s data policies apply to those calls
- Available on all plans, including Free
Private Deployments
For teams requiring full infrastructure control, Private Deployments let you run agents and inference on your own infrastructure:- Custom model endpoints (local, VPC, or third-party)
- Option to hide the managed model catalog
- Zero dependency on external endpoints for sensitive workloads
MCP Tool Security
Agents request explicit permission before invoking MCP tools:- Per-invocation approval by default
- “Always allow” option for trusted tools
- Full visibility into which tools are being called and with what parameters
Responsible AI
Zencoder follows responsible AI practices. To report concerns or incidents related to AI behavior, use the AI Adverse Impact Reporting Form.Data Rights
Depending on your jurisdiction, you may have the right to:- Access your personal information
- Correct inaccuracies
- Request deletion
- Restrict processing
Related
Privacy & Ethics FAQ
Frequently asked questions about data privacy
Private Deployments
Run Zencoder on your own infrastructure
Custom Models
BYOM — configure your own model endpoints
Trust Center
Certifications, controls, and compliance docs