Security

Built with security in mind.

No wild claims. Just the controls, encryption, and limits we actually run. Here’s how your data is protected.

Encryption

All traffic is TLS 1.2+ in transit. Ticket data and configuration are encrypted at rest.

Access control

Role-based dashboard access layered on top of Discord’s own permissions. Least privilege by default.

Monitoring

Continuous health and abuse monitoring across the bot, dashboard, and API, with alerts on anomalies.

Our approach

Security, in practice.

Data protection

Ticket data and configuration are encrypted at rest and in transit. Backups are encrypted and retained only for recovery. Deleted servers are purged within 30 days.

Infrastructure security

The bot requests only the permissions it needs to run support. It never asks for administrator access. You can review and revoke its permissions at any time from Discord.

Authentication

Dashboard access goes through Discord’s OAuth2, so we never handle your password. Sessions are short-lived, and staff access is role-based end to end.

Responsible disclosure

Found something? Report it privately and we’ll respond fast. We never pay ransoms, and we always disclose fixes to the community once resolved.

Security contact

Found a vulnerability?

Report it privately and we’ll acknowledge it within 48 hours. We take every report seriously.

Community

Join the Zextra community

Get help, report issues, suggest features, or talk to the team building Zextra. Questions answered fast.

Join Discord →