Security & trust

Security and data sovereignty, on infrastructure you control.

Zentryc is built around an on-premises model: your monitoring data, credentials, and reports stay inside your network. This page outlines the architecture and the controls that keep operations accountable — signed updates, scoped access, audit trails, and air-gap-capable deployment.

The on-prem trust model

Your data stays in your environment by default.

Zentryc deploys as an appliance inside your network. Telemetry is collected close to the assets it monitors, stored on a data plane you operate, and exposed through a console your own teams administer. There is no mandatory pipeline shipping operational data to a vendor cloud.

  • On-premises data plane — metrics, flows, traces, configs, credentials, and reports live on the appliance you control.
  • No default external egress — nothing is sent off-box without an integration you configure and own.
  • Customer-administered access — you hold the accounts, roles, and keys that govern the platform.
  • Restricted-egress capable — the architecture supports isolated and air-gapped deployments.

See how the platform deploys

zenplus · ncm-summary
ZenPlus configuration management summary showing versioned device backups, credentials, and gateway settings managed on the on-premises appliance
Configuration, credentials, and gateways managed inside the appliance you control.

Platform controls

Controls that keep operations accountable.

Each control is a real capability built into the Zentryc platform — from signed update verification to revocable credentials and a recorded audit trail.

On-premises data plane

Monitoring data, credentials, and reports never leave your network by default. There is no mandatory external telemetry pipeline.

Signed over-the-air updates

Release packages are verified against a dedicated signing key before they are applied, so an appliance only installs builds Zentryc actually published.

Scoped, revocable credentials

Appliance access uses time-bound tokens and API keys that can be rotated or revoked from the console the moment a device is decommissioned.

Role-aware administration

Operators, engineers, and administrators get the access their job needs, separating day-to-day triage from configuration and key management.

Audit trail

Subscription, key, release, and fleet actions are recorded so you can answer what changed, when, and by whom during a review.

Credential vaulting

Reusable SNMP v2c/v3 and Windows credential profiles keep device secrets managed centrally instead of scattered per device.

Controlled gateways & routing

Email and SMS gateways plus channel routing are configured inside the platform, keeping alert delivery under customer control.

Air-gap capable

The architecture supports restricted-egress and isolated deployments for sensitive environments that cannot reach the public internet.

Shared responsibility

Where Zentryc’s job ends and yours begins.

Security is a partnership. Zentryc builds the platform, signs every release, and ships sensible defaults. You own the environment it runs in — the network, the operating system, the accounts, and the keys. These principles describe how the two fit together.

Read the installation guide

Zentryc secures the software supply chain

Release packages are built, signed, and published by Zentryc, and verified against a dedicated signing key before an appliance applies them.

You operate the environment

The host OS, network segmentation, backups, and physical or virtual access to the appliance sit with your infrastructure and security teams.

You administer access and keys

Roles, console accounts, API keys, and device credentials are created, scoped, rotated, and revoked by your administrators inside the platform.

The platform keeps a record

Subscription, key, release, and fleet actions are logged so reviews can establish what changed, when, and by whom — shared visibility for both sides.

Scope of this page

An architecture and trust overview — not a certification claim.

This page describes how the Zentryc platform is designed to handle data and access. It is intended to help your security and infrastructure teams evaluate the architecture during a review.

  • The controls above describe platform capabilities, not formal attestations.
  • We do not represent any specific third-party certification as achieved on this page.
  • For deployment specifics, hardening guidance, or a security questionnaire, contact our team directly.
On-prem by design Signed updates Revocable credentials Role-aware access Audit trail Credential vaulting Controlled gateways Air-gap capable

Evaluate with confidence

Bring your security review to the table.

Talk to our team about deployment, hardening, and data handling for your environment — or start with the install guide and see exactly what runs on the appliance.