Zero Door

Prove what runs on your servers.

Zero Door reads every file by content and judges every change for legitimacy: signature, package, provenance, the process that made it, and whether what runs in memory matches what sits on disk. The one change that fails becomes evidence an auditor can verify offline.

Three pillars

One agent, three answers.

File integrity

A Rust agent hashes files with BLAKE3 and streams only the deltas. Content, not timestamps. Real-time on Linux and Windows.

Compliance evidence

Every action lands in an HMAC-chained audit trail mapped to 12 built-in frameworks. The report exists before the auditor asks.

Software intelligence

Package inventory, CVE exposure and end-of-life status, tied to the files actually present on each machine.

How it runs

From change to verdict.

  1. 01

    Hash

    The agent fingerprints files by content and reports only what changed.

  2. 02

    Enrich

    Each change is checked against a legitimacy registry, package and CVE intelligence and threat feeds.

  3. 03

    Decide

    The operator receives a verdict with severity, not a diff. Noise is silenced at the source.

  4. 04

    Seal

    Findings and actions are chained and signed. Evidence can be verified offline, without an account.

Who it is for

Built for the frameworks you are audited against.

Banking and finance

PCI DSS 4.0 requirement 11.5 and BDDK information systems rules ask for continuous change detection on critical files. Zero Door makes that a by-product of running the fleet.

Healthcare

HIPAA and KVKK special-category data live on servers that change every day. Integrity evidence shows what changed, who caused it and why it was allowed.

Defence and public sector

STANAG and NIST 800-53 environments cannot call home. The same product runs behind your air gap with offline licensing and offline verification.

Air-gapped estates

No feature is cloud-only. Activation uses an offline signed licence token; updates arrive as signed bundles you carry in.

Editions

Same codebase, three ways to run it.

EU-resident SaaS

Operated by Zerone in the European Union. Monthly availability 99.5% on every tier, breach notice within 48 hours.

Self-hosted

Your Kubernetes or Docker Compose, your database, your keys. Full feature parity with SaaS.

Air-gapped

Zero outbound traffic. Offline licence, offline updates, offline evidence verification.

Pricing on request. List prices are quoted in USD and TRY per agent per month; pilots are scoped with you.

The agent

Small, signed, self-updating.

Written in Rust, runs as a service on Linux and Windows or as an ephemeral scan. Adaptive CPU and memory throttling, signed releases, self-update with rollback. Downloads live in the console.

Documentation
12 frameworks

Mapped once, reported everywhere.

  • PCI DSS 4.0
  • HIPAA
  • ISO 27001:2022
  • SOC 2
  • NIST 800-53
  • FedRAMP
  • GDPR
  • NATO STANAG
  • SOX ITGC
  • NIST 800-171 / CMMC L2
  • NERC CIP
  • KVKK and Law 7545

See it on a fleet like yours.

A 30-minute walkthrough or a pilot behind your own air gap.

Book a demo