Skip to main content
Security & Trust

How Customer Zero isolates credentials, audits grants, and hosts data in sovereign Australian infrastructure.

Customer Zero is operated by IKMJ (Ikigai & Majime Pty Ltd), an active Australian private company registered in Victoria. This page describes the controls the platform actually runs under, in the language of the system itself — not the language of marketing. Where a formal certification has not been earned, the underlying control is named so you can verify it directly.

Hosting & data sovereignty

Region

Melbourne, Victoria

The entire production stack runs on Google Cloud Platform in Melbourne, Victoria. Customer data does not leave Australia.

Replication

Single-region, no cross-region failover

Data is not silently copied to overseas regions. Disaster-recovery posture is documented separately to enterprise customers under NDA.

Operating entity

Ikigai & Majime Pty Ltd

The parent entity's site is ikigaimajime.com.au.

Credential isolation

Source-system credentials (Google Ads developer tokens, Meta access tokens, GA4 service accounts, Xero OAuth refresh tokens, and the rest) are never persisted in the application database. They live in Google Secret Manager as opaque versioned resource references — pointers like projects/.../secrets/.../versions/N — and the application resolves them at use.

Plaintext access tokens do not appear in any application table, log line, or error payload. Secret references are recursively redacted from logs by the secret-manager client before they reach the structured log sink. Rotating a compromised credential is a one-call secret-version bump; the next request picks up the new value with no application redeploy.

Access control & tenant scope

Tenant scope is server-derived, never request-derived. The clientId and subscriptionId that gate every query come from the authenticated session cookie, not from any client-supplied parameter. A cross-tenant probe is rejected by the service layer before it reaches Prisma, and the rejection is itself written to the audit log.

Access grants are instance-scoped. A user with access to Google Ads — Acme HQ does not automatically have access to Google Ads — Acme APAC; each instance carries its own grant record that names the source instance, the consumer user, and the AI client runtime (Claude, ChatGPT, Gemini Enterprise) that the grant is valid for.

Churn is a database invariant, not application code. A database trigger atomically deactivates instances, transitions them to CHURNED, and revokes derived grants when a subscription flips to is_active = false. There is no application path that can leave a derived grant alive past its parent subscription.

Audit trail

Every state-changing action — provisioning, granting, rotating, revoking, source connection, source churn — emits an immutable AuditEvent row in the same database transaction as the change it records. Audit rows cannot be retroactively edited; the append-only constraint is enforced at the database layer, not the service layer.

Authenticated operators can read their own tenant's audit log via GET /audit-events. Events carry an actor, a verb, a target resource, and a structured payload — enough to reconstruct any authorization decision in retrospect.

Transport & browser security

HSTS

max-age=31536000; includeSubDomains; preload

Browsers will refuse plaintext HTTP for the entire customerzero.ikmj.com.au subtree for the lifetime of the preload list.

Content Security Policy

script-src 'self'

No third-party script execution, no unsafe-eval, no remote stylesheets. The CSP forbids frames from any origin (frame-ancestors 'none') and disables cross-origin embedding.

Permissions Policy

Camera, microphone, geolocation, payment, USB all disabled

The browser is asked to refuse access to every sensor and device class the platform does not need.

Session

HttpOnly, Secure, SameSite=Lax cookie + CSRF token

Sessions cannot be read by client JavaScript, are never sent over plaintext, and every state-changing request requires a double-submit CSRF token. Public endpoints only.

Operational transparency

Source connections report four honest status classes — Healthy, Needs attention, Stale, Access lost — and the platform does not paint over them with an aggregate "all green" badge. If a customer's reporting surface is green, it is genuinely green; if it is not, the customer sees exactly which source and why.

Idempotent commands (every state-changing endpoint) require an Idempotency-Key header. Replays within the 24-hour TTL return the stored response without re-executing business logic, so a double-submitted form cannot double-charge an account or double-issue a credential.

Compliance posture

Customer Zero does not currently assert SOC 2, ISO 27001, or IRAP certification. Pursuing those certifications is on the platform roadmap; the page will be updated as each is earned.

What the platform does assert, and you can verify directly from the architecture: append-only audit, scoped per-instance grants, secret references rather than persisted secrets, server-derived tenant scope, a database-enforced churn cascade, and a single-region Australian hosting posture with no silent cross-region replication.

Enterprise customers and procurement teams can request a security questionnaire response, a current sub-processor list, and the platform's data-flow diagram from sales@customerzero.app.

Verify it yourself

See the governed endpoint these controls protect.