Privacy Policy
What data the ZERONE platform processes, how we protect it, and the metadata-only principle behind our collection.
This page is a general template for the ZERONE platform and is not legal advice. Where ZERONE is deployed in your environment, your organization is typically the data controller and this policy supports your own privacy program.
1. Scope
This policy explains how the ZERONE GRC platform processes information when it is used to discover assets, connect to endpoints, and collect inventory, compliance and security data. ZERONE may be deployed on-premise or within your own environment; in those cases your organization controls the data and ZERONE acts as a processor under your instructions.
2. What the Platform Processes
- Account & access data — user identities, roles and authentication events for RBAC and audit logging.
- Asset & endpoint data — host fingerprints, asset metadata and agent coverage.
- Software & configuration data — installed software, versions, lifecycle and CIS compliance status.
- Account & identity signals — local accounts, administrators, guest, stale and privileged group memberships.
- Data file metadata — file name, path, extension, size, owner, modified date and sensitivity indicators.
- Findings & risk records — vulnerabilities, compliance gaps and the risks derived from them.
3. The Metadata-Only Principle
By design, the Data Inventory module collects metadata only. It does not collect file contents, passwords, hashes, private keys, tokens or secrets. The platform records attributes about files and systems — never the sensitive material inside them.
4. How the Data Is Used
Collected data is used solely to provide the platform's functionality: building the asset inventory, assessing compliance and vulnerabilities, surfacing risky accounts and data exposure, automating risk creation, and producing dashboards, evidence and reports. It is not sold or used for advertising.
5. How We Protect It
- Role-based access control and, where enabled, multi-factor authentication.
- Secure credential handling for connection credentials, with an encrypted vault.
- A tamper-evident, hash-chained audit trail of sensitive actions.
- Least-privilege access and vendor/customer separation.
- Integrity-verified (SHA-256 / Ed25519) vendor updates.
6. Data Retention
Data is retained for as long as needed to provide the service and to meet your governance, audit and compliance requirements, or as defined in your agreement. On termination, retention and export follow your agreement.
7. Your Rights
Where applicable privacy law (such as GDPR or KVKK) applies, data subjects may have rights of access, rectification, erasure and objection. Because ZERONE typically processes data on your organization's behalf, such requests are handled through your organization's own privacy processes — which the platform's privacy tooling is designed to support.
8. Contact
Questions about this policy? Contact us at [email protected]. See also our Terms of Service.
