{
  "slug": "firezone",
  "category": "mesh-vpns",
  "name": "Firezone",
  "description": "Zero-trust remote access platform built on WireGuard, with clients, gateways and a control plane for group-based access policies. Mostly offered as a hosted service; self-hosting the control plane is not officially supported.",
  "website": "https://www.firezone.dev",
  "source": "https://github.com/firezone/firezone",
  "license": "Apache-2.0",
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 59,
  "coverage": 100,
  "summary": "Firezone scores 59 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 3 of 7 criteria: open source, no ads or data sales and keys stay on devices. It partly meets self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
  "url": "https://privacyratings.com/mesh-vpns/firezone/",
  "markdown": "https://privacyratings.com/mesh-vpns/firezone/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/firezone/firezone/blob/main/elixir/LICENSE",
      "note": "All code is public. The clients and gateway are Apache-2.0, and the control plane and admin portal use the source-available Elastic License 2.0, which is not OSI-approved."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.firezone.dev/privacy-policy",
      "note": "The website uses PostHog analytics and Google Ads tags, and the apps send diagnostics and crash reports."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.firezone.dev/pricing",
      "note": "Funded by paid plans; the privacy policy states personal information is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "device_keys": {
      "title": "Keys stay on devices",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.firezone.dev/kb/reference/faq",
      "note": "Traffic is end-to-end encrypted with WireGuard between clients and gateways on your own infrastructure. Firezone states it can never decrypt traffic, including through its relays."
    },
    "self_hosted_control": {
      "title": "Self-hosted coordination server",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.firezone.dev/kb/reference/faq",
      "note": "Gateways run on your own infrastructure, but the control plane is source-available and self-hosting it is not supported."
    },
    "no_connection_logs": {
      "title": "No connection logs by default",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.firezone.dev/kb/reference/cli/headless-linux",
      "note": "Clients send crash reports to Sentry by default. The --no-telemetry flag or FIREZONE_NO_TELEMETRY turns this off."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:00:57.432Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}