Security

Security
is the product.

Lockzero exists to reduce credential risk, not create it. Here’s exactly how we protect your secrets.

AES-256-GCM

Military-grade authenticated encryption for every stored credential.

Zero plaintext logs

Secrets are masked by default and never appear in application logs.

Hash-chain audit trail

Tamper-evident audit log chaining every event to the one before it.

Encryption at rest and in transit

Every credential stored in Lockzero is encrypted before it ever touches a disk. Data moving between your app and our API is equally protected.

We use envelope encryption so that each secret has its own data encryption key (DEK), which is itself wrapped by a master key — limiting the blast radius of any single key compromise.

  • AES-256-GCM encryption for all stored credentials
  • TLS 1.2+ for all data in transit
  • Envelope encryption: per-secret data encryption keys (DEKs) wrapped by a master key
  • Secrets masked by default — never logged in plaintext
  • Role-based access: Owner, Admin, Operator, Viewer
  • Re-authentication required to reveal sensitive credentials
  • Scoped API keys with last-used tracking and revocation
  • 30-min session idle timeout with warning dialog (CMMC AC.L2-3.1.10)
  • Account lockout: 10 failures → 30-min lockout (CMMC AC.L2-3.1.8)
  • 12-char passwords + uppercase/lowercase/digit/special (CMMC IA.L2-3.5.7)
  • Password history: last 12 hashes blocked from reuse (CMMC IA.L2-3.5.8)
  • TOTP MFA with Argon2id-hashed backup codes

Access controls

Fine-grained permissions ensure that the right people can access the right secrets — and nobody else. Every access path is authenticated, scoped, and revocable.

CMMC-aligned: account lockout, 12-char password policy, password history (12 past hashes blocked), 30-min idle session timeout, TOTP MFA, and step-up re-auth gates on sensitive operations.

Full audit trail

Every action on every secret is permanently recorded. Know who did what, when, and from where — with tamper-evident logs you can export to your SIEM.

Our hash-chain design means any retroactive modification to an audit record breaks the chain, giving you confidence that the log reflects exactly what happened.

  • Every secret view, edit, rotation, and deletion is logged
  • Tamper-evident hash-chain audit log
  • Actor, IP, timestamp, object, result on every event
  • Exportable logs for SIEM integration
  • Accessible in-app under Audit Log
  • Infrastructure on AWS with private networking
  • Daily encrypted backups
  • Status transparency at lockzero.io/status
  • Incident response: we notify affected customers within 24 hours

Reliability and availability

Built on hardened AWS infrastructure with redundancy, network isolation, and proactive monitoring — so your secrets are always there when your apps need them.

We publish our status in real time and commit to notifying affected customers within 24 hours of any confirmed incident.

Responsible disclosure

Found a vulnerability? We want to hear from you. Report responsibly and we’ll respond quickly.

security@lockzero.io

We do not currently offer a bug bounty, but we take all reports seriously and will acknowledge receipt within 48 hours.

Compliance

Compliance posture

We’re building toward the certifications your security team expects. Full control matrix at lockzero.io/compliance.

Self-Attested ✓

CMMC Level 1

All 17 FAR 52.204-21 practices implemented. CMMC Level 2 key controls (IA, AC, SC families) also implemented. Full control matrix available on request.

In Progress

SOC 2 Type II

Continuous 6-month observation window underway. Controls mapped to AICPA Trust Services Criteria. Report available to Enterprise customers on NDA.

Planned

Annual Pen Test

Independent third-party penetration test on an annual cadence. Results summarized in the SOC 2 package.

The control layer for every credential you ship.

Stop exposing secrets in environment variables, CI files, Slack messages, and SDK boilerplate. Lockzero keeps them encrypted, governs how they're used at runtime, and audits every call — across OpenAI, Anthropic, Bedrock, Stripe, and 60+ providers.

7-day free trial · no charge until trial ends · cancel anytime
Security — Lockzero Trust Center | Lockzero