Skip to content
About us

We exist so your website has someone in charge.

Zento is a managed WordPress security service based in Lima, Peru. On this page you won't find client logos or brochure phrases - just how we think, how we work and what we work with, so you can decide on information, not promises.

Our story

Why Zento exists

Zento was founded in Lima in 2026 out of an uncomfortable observation: thousands of businesses already depend on their website, but the security of that website is nobody's job. The developer who built it delivered the project and moved on. The hosting provider answers for the server, not for what runs on top of it. And corporate cybersecurity services aren't designed - or priced - for a company of 5 or 50 people.

The ending is the same everywhere: a WordPress site goes months without updates, without backups stored outside the hosting and without anyone watching, until one day Google flags it red or it starts redirecting to a pharmacy. Only then does the owner discover that nobody was ever in charge - at the worst possible moment. And if you manage the site from abroad, distance makes it worse: you usually find out when a customer tells you.

Zento exists to be that someone: responsible for keeping your WordPress monitored, backed up, updated and defended - and the one who answers when something goes wrong.

We work on WordPress and only WordPress, on purpose. It powers over 40% of the web and has its own ecosystem of plugins, themes and vulnerabilities that changes every week. Following it closely is a full-time job - and it's exactly ours.

What we won't tell you

We're a new company, and we'd rather tell you that than hide it. That's why this site has no logos of clients that don't exist, no unverifiable "years of experience", no photos of an inflated team. What it does have: published processes with timelines, commitments in writing, and a report with evidence at the end of every job. We'd rather be judged by what you can verify today than by what you'd have to take on faith.

Principles

Principles you can hold us to

These aren't wall values - they're operating rules. If we break one, you have something concrete to call out.

  1. 01

    Every job ends in a report

    What was found, what was done, and the evidence behind it - in every intervention, no exceptions. If the report doesn't arrive, the job isn't finished. It's that simple.

  2. 02

    We talk to you in plain language

    Every technical term gets translated into what actually matters to you: risk, cost and the continuity of your business. If you don't understand something in one of our reports, that's the report's fault, not yours.

  3. 03

    No fine print

    A fixed quote before we start, scopes in writing, and monthly plans with no lock-in. You stay because it works, not because a contract holds you.

  4. 04

    We don't sell with fear

    The risk is real and the numbers show it - but we present them with sources and context, never as an alarm. A security company that needs to scare you into buying has already started manipulating you.

Method

What we work with

Technical competence isn't declared - it's shown. These are the practices we operate on: the same ones you'll find, point by point, in the detail of each service.

Monitoring

Continuous watch over uptime, file integrity and malware. Every cleanup is additionally verified with independent external scanners: we never trust a single source.

Vulnerabilities

Daily tracking of the WordPress ecosystem's vulnerability databases - such as Patchstack and WPScan - so we know which plugin fell before a bot exploits it on your site.

Backups

Automated copies stored outside your hosting, plus test restores: a backup that's never been restored isn't a backup, it's a hope.

Hardening

Two-factor authentication (2FA), least privilege on accounts and permissions, a WAF - a firewall that filters malicious traffic before it reaches your site - and security headers like the ones on this very site.

Recovery

A forensic copy before anything is touched, a cleanup guided by diagnosis - not just "running the scanner" - full credential rotation, and the review handled with Google Safe Browsing and Search Console.

Access

Your credentials live encrypted in a password manager, travel only through secure channels - never by plain-text email - and are rotated at the close of every job.

The test you can run right now

zento.pe runs the same security headers we configure for our clients. Don't take our word for it: check it on securityheaders.com →

Data

Your data and your keys

Working with us means trusting us with two delicate things: your personal data and the keys to your site. We treat both as part of the service, not as paperwork.

The personal data you leave with us - your name, email, whatever you tell us about your site - is processed under Peru's Data Protection Law (Law 29733): we use it only to reply to you and provide the service, we don't share it with third parties for commercial purposes, and you can exercise your rights of access, rectification, cancellation and opposition at any time. And whatever we see inside your site - configuration, content, your customers' data - stays confidential: it isn't used, isn't discussed and isn't published as a "case study" without your written permission.

The full detail, unambiguous, is in the Privacy Policy.

The best way to evaluate us is to write to us.

Tell us about your site and grade the reply yourself: how fast we answer, how clearly we speak, and whether we push you toward something you don't need. We reply within one business day, no strings attached.