SECURITY & OPERATIONAL POLICIES

Security Policies

App is nothing — a subsidiary of DRPCOA ENTERPRISE. Last updated: August 2026.

Data Retention Policy

Relay retention: 0 seconds. ZeroText relay nodes are in-memory only. No message payload, header, routing metadata, or cryptographic identifier is written to disk or any persistent storage at any point during transit.

Message content: 0-second retention
Message metadata: 0-second retention
IP addresses (relay): Not logged
User identifiers: Not stored server-side
Group membership: Client-side only
AI queries: 0-second retention

Cryptographic Standards

Key Exchange — X25519 (Curve25519 ECDH)

~128-bit security. Used for all Diffie-Hellman operations in X3DH handshake and Double Ratchet DH steps. RFC 7748 compliant.

Identity Signatures — Ed25519

128-bit security. All identity keys are Ed25519 keypairs. Messages are signed for authenticity. RFC 8032 compliant. Resistant to fault attacks.

Payload Encryption — AES-256-GCM

256-bit key length. AEAD — provides both confidentiality and authenticity. Hardware-accelerated on ARM and x86. NIST FIPS 197 approved.

Identity Generation — BIP-39 (256-bit Entropy)

12-word mnemonic from 256-bit entropy source. Device OS CSPRNG only. Seed never transmitted. Ed25519 + X25519 keypairs deterministically derived via HKDF.

Vault Encryption — Argon2id + AES-256-GCM

Argon2id KDF for memory-hard passphrase derivation (resistance to GPU/ASIC brute-force). AES-256-GCM for vault content encryption. Client-side only.

Responsible Disclosure & Bug Bounty

App is nothing invites security researchers to responsibly disclose vulnerabilities in ZeroText's application, relay, or web platform. We operate a coordinated disclosure policy with the following commitments:

  • Acknowledgement: Within 48 hours of disclosure
  • Coordinated Disclosure Window: 90 days from initial report
  • Legal Safe Harbor: Good-faith researchers are not subject to legal action
  • Credit: Public acknowledgement upon fix (with researcher permission)

In-Scope Targets

  • ZeroText Android application (com.zerotext.zerotext_mobile)
  • ZeroText relay infrastructure
  • zerotext.drpcoa.com web platform
  • Cryptographic protocol implementation
Report a Vulnerability Securely

Incident Response

In the event of a confirmed security incident affecting ZeroText infrastructure, App is nothing commits to the following response process:

  1. 1
    Contain (0–4 hours): Isolate affected relay nodes and halt potentially compromised services.
  2. 2
    Assess (4–24 hours): Determine scope, nature, and impact of the incident with full forensic investigation.
  3. 3
    Notify (24–72 hours): Notify affected parties and regulators as required by UK GDPR Article 33/34.
  4. 4
    Remediate & Post-Mortem: Deploy patches, publish a post-mortem report, and update security controls.

Penetration Testing Policy

ZeroText infrastructure undergoes regular internal security assessments. Third-party penetration testing requires prior written authorisation from App is nothing. Unauthorised penetration testing is prohibited and may be reported to law enforcement. To request a formal penetration testing engagement, contact appisnothing@drpcoa.com or transmit via our in-built Executive Contact portal.

Privacy Policy Terms of Service