Six-week guided deployment of Zoza Vault alongside your existing tokenization stack. Fixed scope. Explicit exit criteria. Auditor-friendly deliverables.
Teams that are currently running Basis Theory, Skyflow, VGS, or Piiano and have a MageCart-class or CDN-layer breach concern their current stack doesn't cover. Teams preparing for HIPAA / PCI Level 1 audits that want to eliminate Zoza from their compliance scope via zero-knowledge mode. Teams that want the category-defining primitives (pre-TLS encryption, length-hiding padding, constant-time decrypt, iframe isolation) but won't commit to Enterprise pricing until they see them work on their traffic.
The pilot is deliberately narrow. We pick one form (or a small cluster of fields in one product) and migrate it end-to-end, not a whole architecture. That keeps the timeline honest and the deliverables testable.
| Week | Deliverable | Your time |
|---|---|---|
| 0 | Pre-pilot scoping call (60 min). Pick the form, pick the fields, pick the audit deliverable. Sign the DPA. | 1h |
| 1 | Sandbox integration. Vault API key issued. Iframe SDK wired into a staging copy of your form. Round-trip smoke test. | 4h eng |
| 2 | Framework-native wrapper swap (React / Vue / Svelte) or vanilla JS bridge, depending on your stack. Load-test from your production region. | 4h eng |
| 3 | Server-side decrypt path wired into your existing backend. Key-rotation run-through. Zero-knowledge mode evaluation if in scope. | 4h eng |
| 4 | Competitor benchmark run from your region (our harness, your API keys) — numbers published in your private pilot doc. | 2h eng + 1h review |
| 5 | Audit deliverable. Threat model / evidence package / ProVerif report. Our security team co-authors; your audit committee reviews. | 4h review |
| 6 | Go/no-go decision. Production cutover plan OR clean exit (keys revoked, data deleted, account closed). | 2h |
Total customer engineering time: ~20-25 hours over 6 weeks. We've kept it small because the pilot's success criterion is that your existing team can run Vault in production, not that we can.
The pilot ends in one of three states. Every state is documented in writing; no soft outcomes.
Every pilot tier below runs at zero cost to you for the full 6-week window. No credit card, no contract, no usage cap — just the same deliverables and the same engineering access that a paid pilot would have included. We are trading short-term revenue for the right to point at your deployment when talking to the next customer. If that is a fair trade on your side, write to us.
Long-term pricing stays off the table until you have seen the product work on your traffic. When and if we get to that conversation, it will be built around what your real usage turned out to be — not a price we guessed at from a landing page.
products/zoza-vault/benchmarks-vs-competitors/ — we'll run it for you from your region, you can re-run it any time.Email hello@zoza.world with:
We respond within one business day with either a pre-pilot scoping call booking or a pass note (we don't pilot with teams where the fit isn't obvious, to keep the pilot queue short).
Alternative path: submit the full apply-for-key form with volume_tier = 10k-100k or higher and "Pilot program interest" in the use_case_details; our admin team routes it automatically.
No catch. We are trading short-term pilot revenue for the right to talk about your deployment when pitching the next customer (under the case-study terms agreed in advance, with your approval on every published word). What you get during the 6-week window is the same access a paid pilot would have had — dedicated security engineer, benchmark from your region, threat-model doc, HIPAA / PCI evidence package depending on tier. Long-term pricing will be negotiated later, based on what your real usage turns out to look like, and only if you tell us the product is worth paying for.
Yes, and we recommend it. Dual-write (sealed payload + existing tokenized payload) for the pilot window gives you a clean A/B comparison and a zero-risk rollback if you choose no-go. The iframe SDK coexists peacefully with Stripe Elements / Basis Theory Elements / VGS Collect.
We've tried three-week pilots and they collapse into the second week because benchmarking + audit deliverables can't compress. Six weeks is the floor that still delivers a real outcome.
Regulated tier includes wiring walkthrough for SoftHSM (dev / staging) or one production HSM you already own (AWS CloudHSM, YubiHSM, Azure HSM). Hardware procurement is not included; see keystore README for the supported provider matrix.
You can run the ProVerif model (products/zoza-vault/formal-model/vault.pv), the Go test suite, the competitor benchmark harness, and your own pentest inside the pilot scope as explicit engagement. The bug bounty at vault-bounty remains in force for anything in-scope.
See the data retention policy. 7 business days for production data; audit-chain entries referencing your app_id persist indefinitely (they contain no PII).
Start a pilot Apply via self-serve form Back to Vault
Last updated 2026-04-17. © 2026 Zoza. Source code copyright LD-16949/2026-CO.