Small surface, explicit limits

Security begins with what Zilch refuses to collect.

The first pilot is intentionally non-custodial and non-transactional. The controls below describe the required launch boundary, not a certification.

01

No account access

Zilch does not collect financial account credentials, account or card numbers, Social Security numbers, or exact balances through the pilot application.

02

No money movement

The proposed manual pilot cannot move money, initiate payments, hold funds, or confirm that a financial transaction completed.

03

Least data

The application is limited to bounded eligibility categories and contact details. Free-form financial narratives and document uploads are not accepted.

04

Controlled access

Before collection begins, named operators must use individual MFA-protected accounts, least-privilege roles, and auditable exceptional access. Shared administrative accounts are not permitted.

05

Verified release

The production gate requires cross-tenant denial tests, secret and bundle scans, accessibility checks, real endpoint readback, and explicit failure states.

06

Honest outcomes

A pilot participant may record a user-attested outcome. Zilch will not describe that record as bank-confirmed or independently verified.

Reporting

A contact and response procedure will be published before collection.

Applications remain closed until the processor list, retention period, deletion path, incident owner, and reporting contact are approved and verified in production.