0i0
0i0 World
← Back to Overview
Trust & Verification

Security & Responsible Disclosure

Last updated: October 2026

At 0i0 World, security is the foundation of autonomous agent infrastructure. Operating mission-critical workflows over the WhatsApp Business API demands defense-in-depth architecture, verifiable cryptographic boundaries, and absolute transparency.

1. End-to-End Transport Encryption (TLS 1.3)

All traffic traversing the 0i0 World gateway is protected with mandatory TLS 1.3 transport encryption. Ingress webhooks from Meta's WhatsApp Cloud API, administrative connections, and egress tool executions enforce HTTP Strict Transport Security (HSTS) with preloaded domain settings.

2. Zero-Trust Tool Sandboxing & Isolation

Our runtime implements strict Zero-Trust tool sandboxing. Every external tool invocation (such as queries to internal databases, CRMs, or ERPs) occurs in an isolated ephemeral execution environment. Sensitive transactional operations require cryptographic authorization and two-step verification gates to prevent prompt injection and unauthorized execution.

3. Mexican LFPDPPP Compliance & Tenant Isolation

Data governance is engineered to comply with Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). Multi-tenant memory namespaces are logically and cryptographically partitioned. Customer messaging payloads and persistent semantic context are isolated per tenant.

4. Dedicated Pilot SLAs & SOC 2 Roadmap Readiness

We provide truthful, uncompromised transparency regarding our operational status: Dedicated pilot SLAs and uptime guarantees are defined individually per enterprise engagement. We do not make unverified compliance claims. SOC 2 operational readiness is actively underway on our engineering product roadmap.

5. Responsible Vulnerability Disclosure Policy

Scope & Evaluated Systems

In-Scope: The apex domain (0i0.world), the production edge routing worker, and public WhatsApp webhook listener endpoints. Out-of-Scope: Third-party services (such as Meta's WhatsApp Cloud API infrastructure), Denial of Service (DoS/DDoS) attacks, automated spam scanners that degrade performance, physical intrusions, and social engineering.

Research Guidelines & Safe Harbor

We support ethical security researchers who discover vulnerabilities in good faith. Under our Safe Harbor commitment: (a) Do not access, modify, or destroy customer data; (b) Do not degrade system availability; (c) Allow us a reasonable window to remediate before public disclosure; and (d) Act within applicable legal frameworks.

Reporting Protocol & SLA

Submit detailed vulnerability reports directly to security@0i0.world. Include reproducible proof-of-concept steps, affected endpoints, and remediation recommendations. Our engineering team acknowledges reports within 24 hours and provides triage status updates within 72 hours.

Our official RFC 9116 security contact manifest is published at /.well-known/security.txt. /.well-known/security.txt

Direct Security Contact

For vulnerability disclosures, PGP communications, or urgent infrastructure security alerts, email our engineering security team at security@0i0.world.

security@0i0.world · contact@0i0.world · Luis Acevedo — 0i0 World, Mexico