Mesh VPNs and private networks
Firezone privacy rating
Zero-trust remote access platform built on WireGuard, with clients, gateways and a control plane for group-based access policies. Mostly offered as a hosted service; self-hosting the control plane is not officially supported.
Summary
Firezone scores 59 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 3 of 7 criteria: open source, no ads or data sales and keys stay on devices. It partly meets self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.
Score 59 out of 100. How scoring works
Criteria
-
Yes
Open source Weight 3 of 3 Source-available
Is all the source code needed to run the product public?
All code is public. The clients and gateway are Apache-2.0, and the control plane and admin portal use the source-available Elastic License 2.0, which is not OSI-approved.
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The website uses PostHog analytics and Google Ads tags, and the apps send diagnostics and crash reports.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans; the privacy policy states personal information is not sold.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
Yes
Keys stay on devices Weight 3 of 3
Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
Traffic is end-to-end encrypted with WireGuard between clients and gateways on your own infrastructure. Firezone states it can never decrypt traffic, including through its relays.
-
Partial
Self-hosted coordination server Weight 2 of 3
Can the coordination or control server be self-hosted with open-source software?
Gateways run on your own infrastructure, but the control plane is source-available and self-hosting it is not supported.
-
Partial
No connection logs by default Weight 2 of 3
Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?
Clients send crash reports to Sentry by default. The --no-telemetry flag or FIREZONE_NO_TELEMETRY turns this off.