Trust Center
Every outbound connection
Every connection the shipped software makes that is not your own deployment: your control plane, signal, relay, identity provider and resources are yours and are not listed. For each: purpose, default and how to switch it off.
Control plane
The Inlinea server
| Connection | Purpose | Default | Disable |
|---|---|---|---|
| Anonymous usage metrics | Aggregate, anonymous statistics: version, uptime, counts of objects. No names, addresses or identities | Off | Stays off unless you opt in |
| Update check | Learn that a newer release exists; feeds the About row | On | Blocked egress is harmless: the version fields are omitted and the check retries later |
| Geolocation databases | Country and city for devices and Trust Checks | Fetched at start-up when enabled | Disable geolocation, or place the databases locally and disable updates |
Gateway
The ZERA gateway
| Connection | Purpose | Default | Disable |
|---|---|---|---|
| Geolocation database | Country-based access restrictions and access-log enrichment | Fetched at start-up when missing | Disable geolocation; country restrictions then deny until a database is present |
| Certificate authority | Certificates for the Workspace and for Protected Services on your domains | On when automatic certificates are configured | Supply your own certificates |
| Session engine | Renders Secure Sessions | Loopback inside the gateway only | Not egress: never reachable from outside |
Agent
The Inlinea Agent
| Connection | Purpose | Default | Disable |
|---|---|---|---|
| Traffic Logs stream | Report aggregated connection records to your own control plane | Off until an administrator switches collection on | Switch collection off; no payloads are ever sent |
| Agent Profile reports | Report the applied policy and protection events to your own control plane | On with Agent Profiles | Part of the managed policy; no passcodes, codes or keys are sent |
| Update check | Offer a newer agent release | On | No switch; a blocked host only produces a log line |
| Update download | Fetch and verify an installer | Only on a control-plane update directive or a person's choice | Do not enable auto-update; packages are verified against Inlinea's signing keys |
| Connection metrics | Fleet health: connection type, latency, relay use | Off | Stays off unless enabled by the environment or by your control plane |
| Debug bundle upload | Diagnostics for support | Only on explicit action by a person or your administrator | Never automatic; bundles can be anonymised |
Everything else
Third parties and the extension
- Browser extensionTalks only to the deployment it is connected to, over the same API origin the Workspace uses. No request to Inlinea-operated hosts and no third-party request.
- CertificatesThe edge and the gateway talk to the configured certificate authority only when automatic issuance is configured.
- Standing reviewBefore every release we list every host the software can reach. Any host that is not the deployment's own or on this page is a release blocker.