---
kind: question
zz: "0.4.0"
updated: 2026-10-09
state: draft
rules: https://zriz.io/llms.txt
---
# Is zriz safe? Security and your data

zriz is built so that database passwords and connection strings stay in your network. A value that you do not list in `sensitive` goes to the cloud.

## Does the cloud see my database password? {#database-password}

No, for a database connection. zriz is built so that `zz` or the runner holds the connection string, and the cloud has no database driver.

A different secret can go to the cloud in two cases:

- A value that you did not put in `sensitive` goes to the cloud.
- A secret that you wrote in a pipeline file goes to the cloud with the file.

Put each secret in the file of the [environment](https://zriz.io/docs/words.md#environment). List its name in `sensitive`.

## What never leaves my network? {#never-leaves}

zriz is built so that the `connection` and the `base-url` of a resource stay in your network. Each value in `sensitive` stays too.

- The `connection` of an SQL resource.
- The `base-url` of an HTTP resource.
- Each value whose name is in `sensitive`.
- Each secret that a deployed runner reads from its own environment.

## What goes to zriz.io? {#goes-to-zriz}

The pipeline file and the resource files, without `base-url` and `connection`. Also each value that is not in `sensitive`, and the results that the checks need.

- The pipeline file.
- Each resource file, without `base-url` and `connection`.
- Each environment value whose name is not in `sensitive`.
- The fields of a reply that the checks need. For a check on `body.email`, that field goes.
- After a call fails: a part of the last reply, a maximum of 4096 bytes.
- The status and the times of the run.

zriz is built so that the [runner](https://zriz.io/docs/words.md#runner) removes each secret that it put into a call from each result. The cloud removes secrets again before it stores a [run](https://zriz.io/docs/words.md#run).

The key `evidence` of the runner config, with the value `"none"`, stops the part of the last reply.

## Which connections does the runner make? {#outbound}

Outbound connections only: to zriz.io, and to the resources in its config. zriz is built so that nothing listens. You open no port.

## What can the runner do? {#runner-may}

Only what the allowlist in its own config file permits. zriz is built so that a pipeline cannot make the runner call a different target.

- The runner calls only the resources that its config names.
- It compares each URL, and each redirect, with the origin of the resource: scheme, host, and port.
- On an SQL resource with `read-only`, it refuses a statement that writes. It runs the query in a read-only transaction.
- It fills a `${NAME}` placeholder only in a permitted position, and never in an SQL query.
- A `cli` resource runs only the commands that the config permits.

The config file is in [the runner guide](https://zriz.io/docs/runner.md#write-the-config).

## Can a zriz test change my data? {#change-data}

Yes, when a step writes. An HTTP step can change data. An SQL step on a resource with `read-only` cannot.

| The step uses | Can it change data? |
|---|---|
| An HTTP resource | Yes. |
| An SQL resource with `read-only` | No. |
| An SQL resource without `read-only` | Yes. |
| A `cli` or `browser` resource | Yes. |

Run a test that writes against a test system. For a database, use an account that can only read, and also set `read-only`.

## Is my data kept apart from other orgs? {#data-scope}

Yes. zriz is built so that each record in the cloud belongs to one org. Each query reads the records of one org only.

## What do the logs of zriz hold? {#logs}

zriz is built so that its logs hold ids, kinds, reasons, and times. They hold no request body and no reply body.

## Does zz hold a runner? {#one-interpreter}

No. zriz is built so that `zz` and a runner are two programs. `zz` holds no runner and makes no call to your service.

Each run goes through a runner, and each runner obeys the same rules.

The secrets of a runner on this machine stay in `.zriz/runner/runner.env` on that machine. The cloud never gets them.

## Where is the code? {#where-is-the-code}

The runner is open source. You can read the code that holds your secrets on a deployed runner. `zz` is not open source.

- [github.com/ZrizTech/runner](https://github.com/ZrizTech/runner)
