Privacy by Design

Security that doesn’t surveil your people.

PoisonZero protects your agents’ memory and is engineered to collect as little about your team as technically possible.

How we do it

Built with restraint, not trust.

For DPOs and works councils.

Data minimization by design

Device liveness is a relative countdown a scheduled sweep decrements; a heartbeat resets it. No absolute timestamp is persisted, so the dashboard cannot reconstruct working hours. (GDPR Art. 5(1)(c); relevant to co-determination under German BetrVG §87(1) No. 6.)

Local redaction before anything leaves

Before any content leaves the device, secrets and personal data are stripped and home paths masked. Only added lines of a change are evaluated; review prompts carry only a redacted, length-capped diff.

What Cloud mode sends

Your data residency

Dedicated enterprise instances are provisioned in the customer’s chosen region; the tenant database location follows that choice (Germany/EU/US/Asia). The shared default tier is hosted in Frankfurt.

Encrypted in transit and at rest

All traffic uses TLS. Data at rest is encrypted with AES-256 on Google Cloud.

Private mode

In private mode the daemon contacts the network at most once every 30 days, to a documented update URL. The analysis model runs locally - no content goes to third-party AI APIs. A fully air-gapped offline install and a stand-down kill-switch are available.

Cloud or private: choosing a mode

No presence tracking, no data sale

We don’t profile activity, sell data, or run ad-tech. A data processing agreement (DPA/AVV) is available for enterprise customers. Audit data has retention limits and is deletable on request.

Storage, retention and cleanup

The architecture in detail Read our full privacy policy