What we store

When you connect a Zscaler tenant to the EpicCyber Monitor, we store:
 
• Zscaler configuration data — policy rules, feature flags, entitlements, network infrastructure, RBAC, and application inventory pulled read-only from your tenant.
• Usage and adoption metrics and, if ZDX is licensed, device health/latency summaries.
• Account records — your company name, the account owner’s name and email, and tenant metadata.
• API credentials — your read-only Zscaler OAuth client_id / client_secret, stored encrypted in a dedicated secrets vault (1Password), never in the Monitor database.
 
We do not collect personal end-user data, individual browsing activity, or endpoint content.

How to request deletion

Email [email protected] from your account-owner address with the subject “Data removal request”, or contact your EpicCyber representative. We’ll confirm the scope with you (single tenant or full account) before proceeding.
 
You can also revoke our access yourself at any time by deleting the API client in your Zscaler ZIdentity console — that immediately stops all future syncs.

What we delete

On a confirmed removal request we:
 
1. Delete the stored credentials — the API client entry is removed from the 1Password vault.
2. Purge collected configuration, policy, monitor, and metrics data for the affected tenant(s) from the Monitor.
3. Mark the tenant Decommissioned and remove it from your Monitor.
4. On request, remove your company and user records entirely.

How long it takes

Removal is completed within 30 days of a confirmed request; in practice the data purge runs on the next sync cycle (typically within 24 hours). We’ll confirm in writing once it’s done.

Need help?

Have questions about your data, or want to confirm what we hold before making a request? We’re happy to help. Reach us at [email protected].