How your credentials are handled
Zorabot stores three secrets for you: your bot token, your Sythe password and the captured session. All three are encrypted at rest and none of them is ever shown again - not to your staff, not to you, not on any page.
What the implementation actually does
- Tokens, passwords and session cookies are stored only as ciphertext (Fernet, symmetric encryption); nothing sensitive is written in plain text.
- Passwords typed in Discord go through a popup form, never through a command option that lingers in the channel's history.
- Every action Zorabot takes under your name - a bump, a vouch, a PM, a price edit - is written to an append-only event log and mirrored into your own Discord log channel.
- Access control is enforced on every single request; there is no cached session that outlives a revocation.
We do not claim certifications we do not hold, and secrecy is not one of our controls - the protections above are simply how the system is built.