# Firezone privacy rating

Zero-trust remote access platform built on WireGuard, with clients, gateways and a control plane for group-based access policies. Mostly offered as a hosted service; self-hosting the control plane is not officially supported.

## Summary

Firezone scores 59 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 3 of 7 criteria: open source, no ads or data sales and keys stay on devices. It partly meets self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.

- Website: https://www.firezone.dev
- Source code: https://github.com/firezone/firezone
- License: Apache-2.0
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Home page trackers: none found
- Category: [Mesh VPNs and private networks](https://privacyratings.com/mesh-vpns/)
- Grade: D (59/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | All code is public. The clients and gateway are Apache-2.0, and the control plane and admin portal use the source-available Elastic License 2.0, which is not OSI-approved. | https://github.com/firezone/firezone/blob/main/elixir/LICENSE |
| No trackers or telemetry | No | The website uses PostHog analytics and Google Ads tags, and the apps send diagnostics and crash reports. | https://www.firezone.dev/privacy-policy |
| No ads or data sales | Yes | Funded by paid plans; the privacy policy states personal information is not sold. | https://www.firezone.dev/pricing |
| Independent audit | No | No independent audit is published. |  |
| Keys stay on devices | Yes | Traffic is end-to-end encrypted with WireGuard between clients and gateways on your own infrastructure. Firezone states it can never decrypt traffic, including through its relays. | https://www.firezone.dev/kb/reference/faq |
| Self-hosted coordination server | Partial | Gateways run on your own infrastructure, but the control plane is source-available and self-hosting it is not supported. | https://www.firezone.dev/kb/reference/faq |
| No connection logs by default | Partial | Clients send crash reports to Sentry by default. The --no-telemetry flag or FIREZONE_NO_TELEMETRY turns this off. | https://www.firezone.dev/kb/reference/cli/headless-linux |

Source: https://privacyratings.com/mesh-vpns/firezone/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/mesh-vpns/firezone.md
