For business

ZRAZU for business

Control over a domain portfolio for a team: who can do what, what actually happened, and how to stop it if something goes wrong.

Team roles and access

You invite a person to one of the roles; what exactly each one allows is visible right in the account.

Team roles in the ZRAZU account
RoleWhat it allows
OwnerEverything, including managing people, keys and the payment method.
AdminDomains, DNS, certificates and money.
TechDNS and certificates; no access to money.
AccountantInvoices, acts, balance; no access to DNS.
Read-onlySee everything, change nothing.

The exact rights of each role are to be announced. A person’s API key is never stronger than their role.

API keys under control

  • A key is issued from a rights template, not “everything”: read-only, edit DNS, monitoring, auto-renew with a spend limit.
  • A key is scoped to specific domains; for rights that spend money, a domain list is mandatory — “all, including future ones” isn’t available.
  • A key’s conditions are an IP range and a monthly call or spend limit; going over answers with a code and when the limit resets.
  • Rights in the “ownership and irreversible” class (remove the transfer lock, change nameservers) need confirmation by a second owner or a 24-hour wait before activation. A “Revoke all keys” button sits on the same screen.
  • An assistant (a model) connects through OAuth, not a copied key: read-only by default, “money” rights are a separate checkbox with a limit, and “ownership and irreversible” rights are never granted through OAuth at all.

Rights catalog and danger classes

Action log

  • Every domain has its own event history: DNS, certificates, money, sign-in and access, support, plans — all in one place.
  • Who on our team opened your domain’s record or read its contacts is logged too, not just changes; a separate person reviews the log once a month.
  • The team’s sign-in log in the account is kept for 30 days.

Locks and Registry Lock

Transfer lock
On by default for every domain; removing it requires typing the domain name to confirm.
Contact lock
On by default: while it’s on, the owner’s contacts can’t change. Removing it takes a fresh sign-in and a 72-hour pause; during the pause we don’t issue a transfer code, and any owner can cancel.
DNSSEC
We check the signature chain in monitoring; signing the zone right from the account is to be announced.
Registry Lock (.ua)
A lock at the registry level itself is to be announced: it depends on an answer from the .ua zone administrator. For other zones — wherever the registry itself supports it.

We notify all domain owners about a change of nameservers, contacts, locks, or a sign-in from a new device; critical notifications can’t be turned off.

Portfolio inventory

Add domains as a list, a CSV file, or a Cloudflare import — registration stays where it is, this isn’t a transfer. At launch, inventory and monitoring are free for the first 25 domains.

Certificates are visible across all domains, including ones we didn’t issue: someone else’s certificate issued for your domain shows up through Certificate Transparency logs — a signal of compromise or shadow IT, not just a list of your own certificates.

Add domains to monitoring

SLA

A formal SLA with compensation for corporate contracts isn’t defined yet — to be announced. General commitments during an incident are already public.

Incident commitments on the status page

FAQ

Does the .ua registry support Registry Lock?

Still to be announced: it depends on an answer from the zone administrator, not only on us. Transfer lock and contact lock already work today for every domain.

Can an API key be scoped to a single domain?

Yes: when issuing a key you choose which domains it applies to. For rights that spend money, a domain list is mandatory — no “all, including future ones”.

How long is the action log kept?

The team’s sign-in log in the account is kept for 30 days. Each domain’s history shows everything that happened to it: DNS, certificates, money, sign-in and access, support, plans.

Is there an SLA with compensation?

There isn’t a formal SLA with compensation for corporate contracts yet — to be announced. General incident commitments are described on the status page.

What can an AI assistant connected through MCP see?

Read-only by default. Rights that spend money are granted as a separate checkbox with a limit; “ownership and irreversible” rights are never granted through OAuth.

Invite your team Contact us