| Organization | The customer's tenant. The boundary of access, metering, and audit |
| Project | The application. It has a public address, version history, and configuration |
| Environment | The target of a deployment and the scope of a configuration. Every project is born with Production |
| Service | A unit that runs inside the project: web application, internal service, continuous process, or scheduled task |
| Build | The process that turns code into an artifact |
| Artifact | The built image, immutable, identified by a unique fingerprint |
| Version | The complete configuration of a deployment: artifact, variables, resources, and address. Immutable |
| Active version | The version receiving traffic |
| Deployment | A deployment, with its state machine and its history |
| Deployment attempt | A deployment request that may have failed before committing a version |
| Operation | The unit of long-running work: it has state, progress, and a cancellation window |
| Evidence | The object correlating logs, events, and failures from a moment, with secrets protected |
| Variable | Readable configuration the application reads from its environment |
| Secret | A sensitive value. It goes in once and cannot be read afterwards |
| Source | The repository the project deploys from — one per project. Each service chooses the folder and the reference |
| Canonical address | A project's public address. Each web service has only one: changing it releases the previous one once the new one is live |
| Zone | The subzone of your company's domain delegated to Zero |
| Delegation | Publishing the four NS records that hand the subzone to Zero |
| Catalog | The set of what the platform accepts. Outside it, nothing is expressible |
| Ready | An instance that accepts TCP connections on the service's port. Only ready instances receive traffic |
| Verification level | How much the deployment proved: Image checked → Configuration applied → Application answering → Address confirmed |
| Network | Groups projects of the organization that can be authorized to call each other. A project joins with one of its environments |
| Access permission | Lets a project in the network reach another project's service, on the service's port. Given by the called project |
| Exposure | Public, with an internet address, or Internal, reachable only through the network |
| Name on the network | A service's internal name: <name>.zero.internal, unique in the network and resolved by the network of whoever asks |
| Internal entry | A Gateway entry that exists only inside a network and leads each path to a service |
| Reserved | What a service is guaranteed in CPU or memory |
| Maximum | The ceiling a service may reach |