Security
Malware checks across ZeroLog workspaces
Local malware checks cover regular and anonymous workspaces. Existing Windows VMs still need protection verified inside each guest.
ZeroLog runs local file checks and monitors suspicious activity in container workloads. File scanning now includes personal agent workspaces and configured host directories, alongside regular and anonymous workspaces. Scanner findings contain detection metadata, without file contents or command output.
The old scheduled scan that wrote findings to disk has been retired. Sensor state, queues and diagnostics use temporary memory storage. This does not mean every ZeroLog service is free of retained records: account data, billing records and saved work remain separate.
Container monitoring does not prove protection inside a virtual machine. Existing Windows VMs still need a verified guest setup. The setup prepared for new Windows guests enables local Defender checks and disables automatic sample submission.
File checks have size and resource limits. A skipped or failed scan is reported as incomplete, rather than counted as clean. Coverage and guest verification remain separate checks; this update does not claim that every file or VM has been scanned.