NetzSec Logo
All policies
LegalUpdated September 4, 2026

Confidentiality & Data Handling

How ZeroTrace hardware and software handle data during authorized engagements, why NetzSec is not a processor of your client data, and how NDAs and DPAs are handled for business customers.

This policy is issued by NetzSec and applies across everything we operate, including the ZeroTraceproduct line (zerotrace.one and its subdomains). Where it says “NetzSec” or “we,” that covers ZeroTrace too.

1. Overview

This policy explains how the ZeroTrace product line handles data, and is written for the professionals and organizations who use it in the field, penetration testers, red teams, investigators, and security labs, who often work under confidentiality obligations to their own clients.

The short version: ZeroTrace tools are built to run locally. NetzSec does not receive, store, or have access to the target, network, or client data you collect or process during an engagement. Using ZeroTrace does not introduce NetzSec as a third party into that data.

This policy sits alongside our Privacy Policy and Terms of Service.

2. Local by design

  • No telemetry. The tools do not collect usage analytics or send your activity to us.
  • No account required to operate. Hardware devices and installed software run without signing in to a NetzSec account for day-to-day use.
  • No cloud processing of engagement data. Captures, scans, logs, and results stay on the device you run them on, the hardware unit, the paired phone, or your own computer.

3. Hardware devices

ZeroTrace hardware operates over Bluetooth LE and USB only, with no internet connection of its own. Everything a device captures is held on the device or on the phone you pair it with over a local Bluetooth LE link. Nothing a device captures is transmitted to NetzSec, and there is no cloud account behind it.

4. Desktop software

Installed ZeroTrace software contacts NetzSec only to activate and validate a license. That exchange carries license and device identifiers for the activation check, it does not carry your engagement, target, or client data. After activation the software continues to work offline.

Any other outbound network traffic is the tool performing the task you direct it to, for example, the OSINT suite querying the public sources you select. That traffic goes to those third-party sources on your instruction, not to NetzSec, and we neither see nor retain its contents.

5. NetzSec is not a processor of your engagement data

Because no target, network, or client data you handle during an engagement reaches NetzSec, NetzSec does not act as a data processor or sub-processor of that data. There is no NetzSec-side copy of it, no remote log of it, and nothing for us to disclose.

For a client evaluating whether a third-party tool may be used on their systems, this is the key point: bringing a ZeroTrace tool into an engagement does not add a new party to the client's data flow and does not place their data outside the tester's control.

The only personal data NetzSec holds is what is needed to run the business itself, such as account, order, licensing, and billing information, which is governed entirely by our Privacy Policy.

6. NDAs and data-processing agreements

For business and enterprise customers who need paperwork on file:

  • Mutual NDA. We are glad to review and counter-sign a reasonable mutual non-disclosure agreement covering a commercial relationship or evaluation. Reach out with your form and we will handle it.
  • Data-Processing Agreement (DPA). A DPA governs a provider that processes personal data on your behalf. Because NetzSec does not process your engagement or client data (see section 5), a DPA is generally not applicable to product use. Where a customer's compliance process still requires a signed statement to that effect, we will provide one.
  • Statement of no network egress. On request we can provide a written attestation of the local-only, no-telemetry behaviour described here, suitable to attach to your own client documentation.

7. Authorized use remains yours

ZeroTrace tools are sold for authorized security testing, research, and training. You are responsible for holding the necessary authorization for any target you assess, and for meeting the confidentiality, legal, and contractual obligations you owe your own clients. This policy describes how our products handle data, it does not grant authorization to test any system.

8. Contact

For NDAs, DPAs, a no-egress attestation, or any question about how ZeroTrace handles data in your environment, contact us through the details on our Imprint. We are happy to support your procurement and security-review process.