Security at Zwiron
Zwiron is built with a zero-trust, agent-based architecture. Your data stays in your network. We never see it, store it, or proxy it.
Agent-Based Architecture
Your data never leaves your network. The Zwiron Agent runs inside your infrastructure as a Docker container or native binary, processing all data locally.
Mutual TLS (mTLS)
Every agent authenticates with mutual TLS using ECDSA P-256 certificates. Certificates are issued and rotated automatically — no manual key management.
No Inbound Ports
Agents connect outbound to the control plane only. No firewall holes, VPN tunnels, or SSH access required. Zero attack surface on your network.
Encryption in Transit
All communications between agents and the control plane use TLS 1.3 with strong cipher suites. WebSocket connections for real-time monitoring are fully encrypted.
Credential Isolation
Database connection credentials are stored locally on your agent — never transmitted to or stored by the control plane. The cloud dashboard never sees your passwords.
Open Source Transparency
The agent, engine, and connector framework are MIT licensed. Every line of code that touches your data is open for inspection, audit, and contribution.
Infrastructure Security
The Zwiron control plane is hosted on enterprise-grade infrastructure with automatic failover, encrypted storage, and DDoS protection. All infrastructure is monitored 24/7 with automated alerting for anomalous activity.
Access Control
The platform supports organization-based access control with role separation. Enterprise plans include SSO integration and RBAC with custom role definitions. All authentication events are recorded in immutable audit logs.
Incident Response
We maintain an incident response plan with defined escalation procedures. In the event of a security incident, affected customers are notified promptly with details of the impact and remediation steps.
Responsible Disclosure
If you discover a security vulnerability, please report it to security@zwiron.com. We appreciate responsible disclosure and will acknowledge your report within 48 hours.