Zscaler issued a response to recent controversy regarding data used for its AI model training.
CEO Jay Chaudhry made references this week to “trillions” of Zscaler’s transaction-level logs being used to train its AI models. Those remarks were shared online, leading to some consternation regarding the potential impact on the firm's zero-trust promise.
In a response from Zscaler CISO Sam Curry, the company stressed its commitment to responsible AI.
“Zscaler does not use customer data to train its AI models,” Curry wrote. “Each customer owns their proprietary information or personal data ... in the Zscaler logs. We only use data or metadata that does not contain customer or personal data for AI model training.”
Curry explained that Zscaler’s architectural approach was founded on data containment, with each customer’s tenant remaining self-contained and under the customer’s control.
The CISO highlighted that sensitive information doesn’t leave this boundary, a deliberate design choice by the company to ensure customer data isn’t used to train AI models beyond a tenant’s environment.
Within this contained environment, Curry claimed, customers are able to use their own data, including logs, transactions, and telemetry to drive improvements that benefited only their organizations, not Zscaler’s.
“This means customers benefit directly from their own signals, whether it’s for risk modeling, AI copilots, or policy enforcement, without having to trade away autonomy or privacy or security," Curry wrote.
On whether privacy limits constrain the ability to benefit from large-scale insights, Curry underlined non‑sensitive metadata based on traffic patterns, aggregated signals, and telemetry are used “to strengthen AI models and improve the overall environment.” This is in line with Shannon’s Information Theory, a mathematical framework Zscaler uses for quantifying, storing, and communicating information.
“Zscaler’s ability to learn from over half a trillion transactions per day leverages a network effect without sacrificing customers’ privacy (specifically and technically a logarithmic utility)," Curry stressed. “To re-emphasize: customers’ proprietary information or personal data in the Zscaler logs is never shared outside of the customer boundary."
Zero to trillions
The company response came after a virtual summit held this week by the Cloud Security Alliance (CSA), in which CEO Chaudhry commented the firm has "over 500 billion transactions per day and hundreds of trillions of signals every day.
"We can use that technology for wonderful threat detection, cyber detection. We’re using it for risk modeling, building copilots, and now more and more agents," Chaudhry said.
The same broadcast saw the CEO espouse the tenet of zero-trust network access (ZTNA), which sees no user, device, or application on the network implicitly trusted, regardless of its placement in or beyond the network perimeter.
Zero trust underpins the Zscaler USP, with the Z in its company name standing for zero.
In their comments this week, both Zscaler's CISO and CEO refer to telemetry derived from the company's customer logs, including endpoint detection and response (EDR) and IoT device data, to help build an AI data fabric for a mesh of different telemetry types. Zscaler AI agents – as unveiled in July – then use the mesh for data collection, investigations, and policies.
Integration is then possible with Zscaler’s managed detection and response (MDR) platform, inherited from its acquisition of MDR provider Red Canary this year. That deal was touted as driving agentic AI security operations with the integration of MDR workflows into its platform.
Later in the week, Zscaler merged its MDR tools into its Zero Trust Exchange platform alongside CrowdStrike’s Falcon EDR service, bolstering Zscaler's SecOps posture while targeting network customers moving from legacy endpoint services to a cloud-native architecture.
Comments