Trust Center
What we can and cannot see
Stated per path, because the honest answer differs by path.
Per path
Three paths, three answers
| Path | What happens to the traffic | Who can read it |
|---|---|---|
| Agent path: device to device | Encrypted end to end between the two devices; a relay forwards packets it cannot open, only when a direct path cannot be made | Only the two devices. Not Inlinea, not your tenant |
| ZERA path: browser to Protected Service | The ZERA gateway in your tenant terminates TLS by design, authenticates the person, enforces policy, then reaches the application over the encrypted private network | Your tenant's gateway, for the request it decides. Not Inlinea's staff |
| Secure Sessions | The session engine in your tenant renders the protocol; Session Evidence is recorded by your gateway and stored in your tenant | Your administrators, in your Control Center |
The control plane
What your tenant keeps
| Data | Purpose | Where |
|---|---|---|
| Users, groups, devices, resources, rules | Identity and policy | Your tenant's control plane |
| Audit, Traffic, ZERA Access, Browser Security logs | Evidence and operations | Your tenant, for the retention you set |
| Session Evidence | Replay of privileged sessions | Your tenant, with your retention and size caps |
| Connection metadata from agents | Health, direct or relayed path, latency | Your tenant; payloads are never sent |
| Browser Security events | Blocked and observed controls, extension lifecycle | Your tenant's Browser Security Log |
Inlinea as your operator
What operating your tenant involves
- Upgrades and replacementInlinea upgrades images, takes daily snapshots and replaces a failed instance. Operations work on the environment, not on your data.
- Health probesMeasured probes of your services' availability; no application content.
- Diagnostics on requestA debug bundle leaves a device only when a person or your administrator asks for it, and can be anonymised.