1. End-to-End Transport Encryption (TLS 1.3)
All traffic traversing the 0i0 World gateway is protected with mandatory TLS 1.3 transport encryption. Ingress webhooks from Meta's WhatsApp Cloud API, administrative connections, and egress tool executions enforce HTTP Strict Transport Security (HSTS) with preloaded domain settings.
2. Zero-Trust Tool Sandboxing & Isolation
Our runtime implements strict Zero-Trust tool sandboxing. Every external tool invocation (such as queries to internal databases, CRMs, or ERPs) occurs in an isolated ephemeral execution environment. Sensitive transactional operations require cryptographic authorization and two-step verification gates to prevent prompt injection and unauthorized execution.
3. Mexican LFPDPPP Compliance & Tenant Isolation
Data governance is engineered to comply with Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). Multi-tenant memory namespaces are logically and cryptographically partitioned. Customer messaging payloads and persistent semantic context are isolated per tenant.
4. Dedicated Pilot SLAs & SOC 2 Roadmap Readiness
We provide truthful, uncompromised transparency regarding our operational status: Dedicated pilot SLAs and uptime guarantees are defined individually per enterprise engagement. We do not make unverified compliance claims. SOC 2 operational readiness is actively underway on our engineering product roadmap.
5. Responsible Vulnerability Disclosure Policy
Scope & Evaluated Systems
In-Scope: The apex domain (0i0.world), the production edge routing worker, and public WhatsApp webhook listener endpoints. Out-of-Scope: Third-party services (such as Meta's WhatsApp Cloud API infrastructure), Denial of Service (DoS/DDoS) attacks, automated spam scanners that degrade performance, physical intrusions, and social engineering.
Research Guidelines & Safe Harbor
We support ethical security researchers who discover vulnerabilities in good faith. Under our Safe Harbor commitment: (a) Do not access, modify, or destroy customer data; (b) Do not degrade system availability; (c) Allow us a reasonable window to remediate before public disclosure; and (d) Act within applicable legal frameworks.
Reporting Protocol & SLA
Submit detailed vulnerability reports directly to security@0i0.world. Include reproducible proof-of-concept steps, affected endpoints, and remediation recommendations. Our engineering team acknowledges reports within 24 hours and provides triage status updates within 72 hours.
Our official RFC 9116 security contact manifest is published at /.well-known/security.txt. /.well-known/security.txt
Direct Security Contact
For vulnerability disclosures, PGP communications, or urgent infrastructure security alerts, email our engineering security team at security@0i0.world.