Anonymization
IP Address Masking
All IP addresses are /16-anonymized before submission. The last two octets are zeroed:
This preserves network-level information needed for threat intelligence while making it impossible to identify specific hosts.
What Is Shared
What Is Never Shared
Zero Telemetry
Panguard collects zero telemetry about your usage:- No usage analytics
- No crash reports sent externally
- No feature tracking
- No license phone-home beyond initial activation
- No third-party analytics SDKs
- No browser fingerprinting
- No session recording
Data Retention
Opt-Out (Offline Mode)
Threat Cloud sharing can be disabled entirely for air-gapped or privacy-sensitive environments:- No data is submitted to any Threat Cloud instance (public or private)
- Guard continues to function with local detection only (ATR rules, baseline)
- Threat intelligence lookups use only the last-synced local feed cache
- No network connections are made to Threat Cloud endpoints
- All other features remain fully operational
Offline mode reduces detection capability since you lose access to collective threat intelligence.
Consider running a private Threat Cloud instance within your network as a middle ground between
full sharing and complete isolation.
Audit Logging
All data submissions to Threat Cloud are logged locally for audit purposes:
This allows you to verify exactly what data left your machine at any point in time.
Self-Hosted Private Instance
For maximum privacy, run your own Threat Cloud instance:- All threat data stays within your network
- You control retention, access, and deletion policies
- You still benefit from external feed synchronization (ThreatFox, URLhaus, etc.)
- Cross-agent correlation works across your fleet
- No data leaves your network perimeter