Why Security Teams Are Turning to Zero-Knowledge Proofs artwork

Why Security Teams Are Turning to Zero-Knowledge Proofs

The Cybersecurity Podcast with Fexingo: Hacks, Breaches, and Digital Defense Conversations

August 18, 2026

Zero-knowledge proofs have moved from cryptography textbooks into mainstream security operations. In this episode, Lucas and Luna break down how ZK proofs let you verify data without exposing it, and why that's becoming a game-changer for breach response and data sharing.
Speakers: Fexingo
**Fexingo** (0:01)
So, there's a phrase that's been rattling around security circles for a few years now, and it's starting to show up in actual vendor pitches and boardroom decks, not just academic papers. Zero-knowledge proofs.

**SPEAKER_2** (0:13)
Right, and I feel like I've heard the term, but I couldn't explain it to a friend. Like, is it just about not revealing secrets?

**Fexingo** (0:21)
Exactly that, but with a mathematical backbone. A zero-knowledge proof, ZK proof for short, is a way for one party to prove to another that a statement is true without revealing anything beyond the truth of that statement. So you can prove you know a password without sending the password, or prove a transaction is valid without exposing the amounts involved.

**SPEAKER_2** (0:44)
Okay, so it's like saying, trust me, I know the secret, but with math.

**Fexingo** (0:49)
More like, I can prove I know the secret and the math checks out. And for years, this was theoretical, but now it's moving into real security operations. Think about breach response.
If you have to prove to a regulator or an auditor that you've fixed a vulnerability, you might have to share details of that vulnerability, which is exactly what you don't want to do if the fix isn't public yet.

**SPEAKER_2** (1:14)
So, ZK proofs let you say, we fixed it, here's the mathematical proof, but we're not going to tell you the exact flaw.

**Fexingo** (1:22)
Exactly.
And that matters because the window between discovering a vulnerability and patching it is exactly when attackers are scanning for it. So, the less you reveal, the better, but you still need to show good faith to auditors, to cyber insurers, to partners.

**SPEAKER_2** (1:38)
That's a real tension. How do you prove you're doing your job without tipping off the bad guys?

**Fexingo** (1:44)
And that's where ZK proofs come in.
A company can generate a proof that says, this patch addresses the vulnerability, and the auditor can verify it without ever seeing the vulnerable code. There are already startups doing this, and the big cloud providers are starting to offer ZK proof services for exactly this kind of compliance check.

**SPEAKER_2** (2:05)
So it's not just for blockchain anymore. This is becoming mainstream in FOSSEC.

**Fexingo** (2:10)
Right, and it ties into the broader zero trust push. Zero trust is about not trusting anyone by default, but you still need to share data across teams, across companies, across borders.
ZK proofs let you share verification without sharing the underlying data.

**SPEAKER_2** (2:27)
And that's huge for data privacy regulations too, like GDPR.

**Fexingo** (2:33)
Absolutely. You can prove your processing data in a compliant way without exposing the data itself.
That's a powerful tool for security teams who are constantly juggling, we need to show we're compliant, with we need to keep this locked down.

**SPEAKER_2** (2:49)
So if I'm a CISO listening, should I be looking at this now?

**Fexingo** (2:53)
I'd say start the conversation. Not every use case needs a ZK proof, but the ones that do are high stakes.
Vendor risk assessments, incident reporting, audit evidence. And the cost of ZK proofs has dropped dramatically in the last couple of years. It's no longer this exotic thing that only crypto companies can afford.

**SPEAKER_2** (3:15)
That's a relief. Because I remember reading about ZK proofs being super compute intensive.

**Fexingo** (3:21)
They were, and they still can be, but the efficiency gains have been massive. There's a whole field of research on making these proofs faster, and some implementations are now fast enough for real-time verification.
So it's moving from maybe someday to we can do this today.

**SPEAKER_2** (3:38)
And that's a shift we're seeing across security. The tools are becoming more practical, more usable.

**Fexingo** (3:45)
If today's conversation gave you something useful, that's the goal. And the way we keep having these conversations ad-free is listener support. If you're finding value, you can help us out at buymeacoffee.com/vexingo.
Every little bit helps us keep the lights on.

**SPEAKER_2** (4:02)
Yeah, and it's easy to do. Just go to buymeacoffee.com/vexingo.

**Fexingo** (4:09)
But back to the tech. The other thing that's driving ZK-proof adoption is the regulatory environment.
In the last couple of years, we've seen more guidance around breach notification and more scrutiny on how companies handle security incidents. And that's putting pressure on security teams to provide evidence without exposing vulnerabilities.

**SPEAKER_2** (4:31)
And that's exactly what ZK-proofs can do. So it's not just a nice-to-have, it's becoming a compliance must-have.

**Fexingo** (4:39)
Exactly.
And we're already seeing some companies use ZK-proofs in their SOC reports.
Instead of handing over logs and code, they hand over a proof that says we've met the control objectives.
And the auditors can verify that proof without needing access to the sensitive systems.

3 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID