What the runtime processes
Prompts, responses, streamed tokens, retrieved context, tool payloads, and agent plans, all inside your own infrastructure. The runtime makes no outbound call to ZNYX to reach a decision.
Security & trust
ZNYX is designed so that adopting it does not widen your data-flow diagram. Here is exactly what runs where, what we receive, and what we do not claim yet.
Prompts, responses, streamed tokens, retrieved context, tool payloads, and agent plans, all inside your own infrastructure. The runtime makes no outbound call to ZNYX to reach a decision.
Operational metadata by default: trace id, policy decision, detector summary, latency, and scope. Prompt and response bodies are not part of that payload.
ML classifiers and the LLM judge run on an in-boundary inference sidecar, so escalation does not become an exfiltration path.
Enterprise can self-host the control plane as well, for an air-gappable deployment with no ZNYX-operated component in the path.
The client SDKs send an anonymous install ping on first run: a random install id, the SDK and language versions, OS and architecture, and a run count. No prompts, responses, tool arguments, keys, or tenant data, ever. It is on by default and off with ZNYX_TELEMETRY=0, and it fails silently when there is no route out.
Controls
Honest limits
If a questionnaire needs something not listed here, ask us directly rather than inferring it, we would rather answer than have you assume.
Contact the security team →FAQ
What the runtime processes, what the console receives, and how ZNYX itself is built and operated.
Pull the open-source runtime, drop it into your stack, and start enforcing policy in minutes, free, forever. Add the hosted control plane when you want centralized policies, evidence, traces, and team workflows.