Built with security in mind.
No wild claims. Just the controls, encryption, and limits we actually run. Here’s how your data is protected.
Encryption
All traffic is TLS 1.2+ in transit. Ticket data and configuration are encrypted at rest.
Access control
Role-based dashboard access layered on top of Discord’s own permissions. Least privilege by default.
Monitoring
Continuous health and abuse monitoring across the bot, dashboard, and API, with alerts on anomalies.
Security, in practice.
Data protection
Ticket data and configuration are encrypted at rest and in transit. Backups are encrypted and retained only for recovery. Deleted servers are purged within 30 days.
Infrastructure security
The bot requests only the permissions it needs to run support. It never asks for administrator access. You can review and revoke its permissions at any time from Discord.
Authentication
Dashboard access goes through Discord’s OAuth2, so we never handle your password. Sessions are short-lived, and staff access is role-based end to end.
Responsible disclosure
Found something? Report it privately and we’ll respond fast. We never pay ransoms, and we always disclose fixes to the community once resolved.
Found a vulnerability?
Report it privately and we’ll acknowledge it within 48 hours. We take every report seriously.
Join the Zextra community
Get help, report issues, suggest features, or talk to the team building Zextra. Questions answered fast.
Join Discord →