Security & trust
Security and data sovereignty, on infrastructure you control.
Zentryc is built around an on-premises model: your monitoring data, credentials, and reports stay inside your network. This page outlines the architecture and the controls that keep operations accountable — signed updates, scoped access, audit trails, and air-gap-capable deployment.
The on-prem trust model
Your data stays in your environment by default.
Zentryc deploys as an appliance inside your network. Telemetry is collected close to the assets it monitors, stored on a data plane you operate, and exposed through a console your own teams administer. There is no mandatory pipeline shipping operational data to a vendor cloud.
- On-premises data plane — metrics, flows, traces, configs, credentials, and reports live on the appliance you control.
- No default external egress — nothing is sent off-box without an integration you configure and own.
- Customer-administered access — you hold the accounts, roles, and keys that govern the platform.
- Restricted-egress capable — the architecture supports isolated and air-gapped deployments.
Platform controls
Controls that keep operations accountable.
Each control is a real capability built into the Zentryc platform — from signed update verification to revocable credentials and a recorded audit trail.
On-premises data plane
Monitoring data, credentials, and reports never leave your network by default. There is no mandatory external telemetry pipeline.
Signed over-the-air updates
Release packages are verified against a dedicated signing key before they are applied, so an appliance only installs builds Zentryc actually published.
Scoped, revocable credentials
Appliance access uses time-bound tokens and API keys that can be rotated or revoked from the console the moment a device is decommissioned.
Role-aware administration
Operators, engineers, and administrators get the access their job needs, separating day-to-day triage from configuration and key management.
Audit trail
Subscription, key, release, and fleet actions are recorded so you can answer what changed, when, and by whom during a review.
Credential vaulting
Reusable SNMP v2c/v3 and Windows credential profiles keep device secrets managed centrally instead of scattered per device.
Controlled gateways & routing
Email and SMS gateways plus channel routing are configured inside the platform, keeping alert delivery under customer control.
Air-gap capable
The architecture supports restricted-egress and isolated deployments for sensitive environments that cannot reach the public internet.
Shared responsibility
Where Zentryc’s job ends and yours begins.
Security is a partnership. Zentryc builds the platform, signs every release, and ships sensible defaults. You own the environment it runs in — the network, the operating system, the accounts, and the keys. These principles describe how the two fit together.
Zentryc secures the software supply chain
Release packages are built, signed, and published by Zentryc, and verified against a dedicated signing key before an appliance applies them.
You operate the environment
The host OS, network segmentation, backups, and physical or virtual access to the appliance sit with your infrastructure and security teams.
You administer access and keys
Roles, console accounts, API keys, and device credentials are created, scoped, rotated, and revoked by your administrators inside the platform.
The platform keeps a record
Subscription, key, release, and fleet actions are logged so reviews can establish what changed, when, and by whom — shared visibility for both sides.
Scope of this page
An architecture and trust overview — not a certification claim.
This page describes how the Zentryc platform is designed to handle data and access. It is intended to help your security and infrastructure teams evaluate the architecture during a review.
- The controls above describe platform capabilities, not formal attestations.
- We do not represent any specific third-party certification as achieved on this page.
- For deployment specifics, hardening guidance, or a security questionnaire, contact our team directly.
Evaluate with confidence
Bring your security review to the table.
Talk to our team about deployment, hardening, and data handling for your environment — or start with the install guide and see exactly what runs on the appliance.