Privacy by Design

Security that doesn’t surveil your people.

PoisonZero protects your agents’ memory and is engineered to collect as little about your team as technically possible.

Data minimization by design

Device health is a relative countdown, not a timestamp. We store no record of when your people are at their machines.

🔒

Local redaction before anything leaves

Secrets and personal data are stripped and paths masked on-device. Only added, redacted lines are sent for a verdict.

🌍

Your data residency

Dedicated instances run in your chosen region (Germany, EU, US or Asia). The shared tier stays in Frankfurt.

🔐

Encrypted in transit and at rest

TLS on the wire, AES-256 at rest.

🛡

Private mode

One network ping every 30 days to a documented URL. The analysis model runs fully on-device. Air-gapped offline install available.

🚫

No presence tracking, no data sale

We don’t profile activity, sell data, or run ad-tech.

Technical detail

For DPOs and works councils.

Device liveness is a relative countdown a scheduled sweep decrements; a heartbeat resets it. No absolute timestamp is persisted, so the dashboard cannot reconstruct working hours. (GDPR Art. 5(1)(c); relevant to co-determination under German BetrVG §87(1) No. 6.)

Before any content leaves the device, secrets and personal data are stripped and home paths masked. Only added lines of a change are evaluated; review prompts carry only a redacted, length-capped diff.

Dedicated enterprise instances are provisioned in the customer’s chosen region; the tenant database location follows that choice (Germany/EU/US/Asia). The shared default tier is hosted in Frankfurt.

All traffic uses TLS. Data at rest is encrypted with AES-256 on Google Cloud Firestore.

In private mode the daemon contacts the network at most once every 30 days, to a documented update URL. The analysis model runs locally — no content goes to third-party AI APIs. A fully air-gapped offline install and a stand-down kill-switch are available.

A data processing agreement (DPA/AVV) is available for enterprise customers. Audit data has retention limits and is deletable on request.

Read our full privacy policy