Trust Center
Data residency and sovereignty
Stated per data class, so a procurement questionnaire can be answered from this page.
Per data class
Where each kind of data lives
| Data | Where it lives | Who controls it |
|---|---|---|
| Identity, groups, Access Rules and configuration | Your tenant's control plane, on its persistent disk | Your administrators, through roles you define |
| Audit, ZERA Access and Browser Security logs | Your tenant, kept for the retention you set | Your administrators |
| Traffic Logs | Off until you switch collection on, then sent only to your tenant | Your administrators |
| Session Evidence | Recorded by the ZERA gateway and stored in your tenant, with your retention and size limits | Your administrators |
| Application traffic on the agent path | Encrypted end to end between devices, never readable by Inlinea | Only the two devices |
| Application traffic through ZERA | Terminated by the ZERA gateway in your tenant to enforce policy | Your Access Rules |
| Backups | Daily snapshots of your tenant's disk, in your tenant's region | Inlinea, as your operator |
On-premises, every row stays in your own data center.
Deployment options
Three ways to keep it where it must stay
Retention and exit
Your retention, your exit
- Retention you setPer log stream in Logs Settings, with size caps for Session Evidence. Expired records are removed on schedule.
- Export at any timeEvery log exports; configuration is available through the API.
- Deletion when you leaveAt the end of the contract your tenant and its snapshots are deleted on the schedule in your agreement, and we confirm it in writing.