Legal
Privacy policy
Last updated July 9, 2026
This Privacy Policy explains what information Cerberus collects, how we use it, and the choices you have. Cerberus is built around Zero Trust principles, and we apply the same care to the data you entrust to us. Your network traffic flows peer-to-peer and does not pass through our servers.
1. Scope
This policy applies to the Cerberus website, the management console, and the client applications provided by SXGuard ("Cerberus", "we", "us").
It does not cover third-party services you connect to Cerberus, such as your identity provider or cloud infrastructure, which are governed by their own policies.
2. Information we collect
Account information such as your name, work email, organization, and role, provided by you or your identity provider when you sign in.
Network metadata required to coordinate connections, including peer identifiers, public keys, and the coordination signals used to establish encrypted tunnels between your devices.
Product and diagnostic data such as client version, operating system, and error reports, used to keep the service reliable.
We do not inspect, store, or proxy the contents of your traffic. Data between your peers is end-to-end encrypted and travels directly between them.
3. How we use information
To provide and secure the service, authenticate users, coordinate peer connections, and enforce the access policies your administrators define.
To maintain reliability and security, including troubleshooting, abuse prevention, and capacity planning.
To communicate with you about your account, security notices, and product updates you have opted into.
4. Sharing and disclosure
We do not sell your personal information. We share it only with service providers who process data on our behalf under contract, and only as needed to run the service.
We may disclose information where required by law, or to protect the rights, safety, and security of our users and the service.
5. Data security
Connections are secured with modern cryptography, and access to internal resources is authenticated on every request rather than trusted by network location.
We apply least-privilege access controls, encryption in transit and at rest, and continuous monitoring across our infrastructure.
6. Data retention
We keep account and configuration data for as long as your organization maintains an active account, and delete or anonymize it within a reasonable period after closure.
Diagnostic and log data is retained only as long as needed for security and reliability.
7. International transfers
Cerberus may process information in countries other than where you are located. Where we transfer data across borders, we use appropriate safeguards consistent with applicable law.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
To exercise these rights, contact us using the details below. We will respond within the timeframes required by applicable law.
9. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you through the service.
10. Contact us
Questions about this policy or your data can be sent to privacy@cerbersec.io, or through the contact page on this site.