ZERONE GRC
Core GRC
GovernanceRisk ManagementCompliance ManagementControlsPolicy Management
Security & Operations
Incident ManagementAsset InventoryEvidence ManagementIntegrationsReports & Dashboards
Assurance & Continuity
Vendor RiskBusiness Continuity / BIAAudit & FindingsAction PlansData Inventory
Explore the platformPricing
Security & Compliance
ISO 27001CIS ControlsNIST CSFNIST 800-53PCI DSS
Privacy & Governance
GDPRSOC 2COBITITILISO 22301 / BCM
Internal & Local
Internal PoliciesLocal RegulatoryData ClassificationBCM RequirementsCustom Frameworks
See framework coverage
By team
For GRC TeamsFor Information SecurityFor Risk ManagementFor Compliance Teams
By use case
For Internal AuditFor IT OperationsFor Executive ManagementFor Vendors / Third Parties
Explore the platformHow it works
Legal

Privacy Policy

What data the ZERONE platform processes, how we protect it, and the metadata-only principle behind our collection.

Last updated: 1 June 2026

This page is a general template for the ZERONE platform and is not legal advice. Where ZERONE is deployed in your environment, your organization is typically the data controller and this policy supports your own privacy program.

1. Scope

This policy explains how the ZERONE GRC platform processes information when it is used to discover assets, connect to endpoints, and collect inventory, compliance and security data. ZERONE may be deployed on-premise or within your own environment; in those cases your organization controls the data and ZERONE acts as a processor under your instructions.

2. What the Platform Processes

  • Account & access data — user identities, roles and authentication events for RBAC and audit logging.
  • Asset & endpoint data — host fingerprints, asset metadata and agent coverage.
  • Software & configuration data — installed software, versions, lifecycle and CIS compliance status.
  • Account & identity signals — local accounts, administrators, guest, stale and privileged group memberships.
  • Data file metadata — file name, path, extension, size, owner, modified date and sensitivity indicators.
  • Findings & risk records — vulnerabilities, compliance gaps and the risks derived from them.

3. The Metadata-Only Principle

By design, the Data Inventory module collects metadata only. It does not collect file contents, passwords, hashes, private keys, tokens or secrets. The platform records attributes about files and systems — never the sensitive material inside them.

4. How the Data Is Used

Collected data is used solely to provide the platform's functionality: building the asset inventory, assessing compliance and vulnerabilities, surfacing risky accounts and data exposure, automating risk creation, and producing dashboards, evidence and reports. It is not sold or used for advertising.

5. How We Protect It

  • Role-based access control and, where enabled, multi-factor authentication.
  • Secure credential handling for connection credentials, with an encrypted vault.
  • A tamper-evident, hash-chained audit trail of sensitive actions.
  • Least-privilege access and vendor/customer separation.
  • Integrity-verified (SHA-256 / Ed25519) vendor updates.

6. Data Retention

Data is retained for as long as needed to provide the service and to meet your governance, audit and compliance requirements, or as defined in your agreement. On termination, retention and export follow your agreement.

7. Your Rights

Where applicable privacy law (such as GDPR or KVKK) applies, data subjects may have rights of access, rectification, erasure and objection. Because ZERONE typically processes data on your organization's behalf, such requests are handled through your organization's own privacy processes — which the platform's privacy tooling is designed to support.

8. Contact

Questions about this policy? Contact us at [email protected]. See also our Terms of Service.