Security Policies
App is nothing — a subsidiary of DRPCOA ENTERPRISE. Last updated: August 2026.
Data Retention Policy
Relay retention: 0 seconds. ZeroText relay nodes are in-memory only. No message payload, header, routing metadata, or cryptographic identifier is written to disk or any persistent storage at any point during transit.
Cryptographic Standards
Key Exchange — X25519 (Curve25519 ECDH)
~128-bit security. Used for all Diffie-Hellman operations in X3DH handshake and Double Ratchet DH steps. RFC 7748 compliant.
Identity Signatures — Ed25519
128-bit security. All identity keys are Ed25519 keypairs. Messages are signed for authenticity. RFC 8032 compliant. Resistant to fault attacks.
Payload Encryption — AES-256-GCM
256-bit key length. AEAD — provides both confidentiality and authenticity. Hardware-accelerated on ARM and x86. NIST FIPS 197 approved.
Identity Generation — BIP-39 (256-bit Entropy)
12-word mnemonic from 256-bit entropy source. Device OS CSPRNG only. Seed never transmitted. Ed25519 + X25519 keypairs deterministically derived via HKDF.
Vault Encryption — Argon2id + AES-256-GCM
Argon2id KDF for memory-hard passphrase derivation (resistance to GPU/ASIC brute-force). AES-256-GCM for vault content encryption. Client-side only.
Responsible Disclosure & Bug Bounty
App is nothing invites security researchers to responsibly disclose vulnerabilities in ZeroText's application, relay, or web platform. We operate a coordinated disclosure policy with the following commitments:
- Acknowledgement: Within 48 hours of disclosure
- Coordinated Disclosure Window: 90 days from initial report
- Legal Safe Harbor: Good-faith researchers are not subject to legal action
- Credit: Public acknowledgement upon fix (with researcher permission)
In-Scope Targets
- ZeroText Android application (com.zerotext.zerotext_mobile)
- ZeroText relay infrastructure
- zerotext.drpcoa.com web platform
- Cryptographic protocol implementation
Incident Response
In the event of a confirmed security incident affecting ZeroText infrastructure, App is nothing commits to the following response process:
-
1
Contain (0–4 hours): Isolate affected relay nodes and halt potentially compromised services.
-
2
Assess (4–24 hours): Determine scope, nature, and impact of the incident with full forensic investigation.
-
3
Notify (24–72 hours): Notify affected parties and regulators as required by UK GDPR Article 33/34.
-
4
Remediate & Post-Mortem: Deploy patches, publish a post-mortem report, and update security controls.
Penetration Testing Policy
ZeroText infrastructure undergoes regular internal security assessments. Third-party penetration testing requires prior written authorisation from App is nothing. Unauthorised penetration testing is prohibited and may be reported to law enforcement. To request a formal penetration testing engagement, contact appisnothing@drpcoa.com or transmit via our in-built Executive Contact portal.