ZoraBOT

How your credentials are handled

Zorabot stores three secrets for you: your bot token, your Sythe password and the captured session. All three are encrypted at rest and none of them is ever shown again - not to your staff, not to you, not on any page.

What the implementation actually does

  • Tokens, passwords and session cookies are stored only as ciphertext (Fernet, symmetric encryption); nothing sensitive is written in plain text.
  • Passwords typed in Discord go through a popup form, never through a command option that lingers in the channel's history.
  • Every action Zorabot takes under your name - a bump, a vouch, a PM, a price edit - is written to an append-only event log and mirrored into your own Discord log channel.
  • Access control is enforced on every single request; there is no cached session that outlives a revocation.
We do not claim certifications we do not hold, and secrecy is not one of our controls - the protections above are simply how the system is built.