Glossary
The words we use, and what they mean.
Every term the product and this site use, in one place.
Ways in
Access
| Term | Meaning |
|---|---|
| ZERA | Zero Endpoint Resource Access: the agentless capability. Reach an approved resource from the browser with nothing installed and no network exposure. |
| Inlinea Agent | The installed mode: the inlinea service and command line and the Inlinea desktop app. Joins a device to the encrypted private network. |
| Workspace | The end-user portal: one branded front door to Protected Services, Secure Sessions and Bookmarks, per group. |
| Studio | The design workbench for the Workspace: brand, appearance, structure, languages, with draft, review and publish. |
| Protected Service | A private application published through the ZERA gateway: HTTPS, TLS passthrough, TCP or UDP. |
| Secure Session | RDP, SSH, VNC or Telnet opened in a browser tab, terminated at the gateway and rendered by the session engine. |
| Bookmark | A link to a SaaS or public application placed in the Workspace beside private ones. |
| Control Center | The administrator application: identity, access, policy, operations and insights. |
Policy
Control
| Term | Meaning |
|---|---|
| Access Rule | A grant from groups to resources, the unit of policy. Nothing is reachable without one. |
| Trust Check | A condition a device must meet: operating system version, agent version, country, network range or running process. |
| Agent Profile | Per-group control of what the agent shows, which settings the organisation owns, and tamper protection. |
| Browser Security | Admission for attested browsers and in-page controls: clipboard, print, transfer, screen capture, watermark, focus. |
| Attestation | A short-lived, signed token that proves a browser is enrolled and alive, verified by the gateway on every request. |
| Access Diagnostics | Step-by-step evaluation of the real rules for a person and a resource, with simulation. |
| Sign-in protection | Attempt limits and blocked addresses for typed credentials, with named reasons and an unblock action. |
| Enrollment Key | A key that admits devices to the private network without an interactive sign-in, with scope and expiry. |
Network and operations
Network, evidence and operations
| Term | Meaning |
|---|---|
| Private Network | The encrypted, peer-to-peer network between devices, built on WireGuard®, with relay as a fallback. |
| Routing device | An agent that connects a whole network behind it: a site, a cloud network, the private side of ZERA. |
| QuietLink | Tunnels that open only when traffic asks for them and close when it stops. |
| Sovereign Outlink | Internet egress through exit gateways on the customer's own devices, with failover and a fixed address. |
| Inlinea Outlink | Regional egress run by Inlinea with fixed egress addresses. |
| Session Evidence | The server-side recording of a Secure Session, keystrokes optional, replayed in the Control Center. |
| Audit, Traffic, ZERA Access and Browser Security logs | The four log streams, each with a summary, filters, export and retention. |
| Pulse, Live Fabric, Live Sessions | The Operations views: health and attention; the network as a live topology; who is connected now, with sign-out everywhere. |
| Point of presence | A location where a tenant's services run. A tenant has a primary point of presence and can have members. |