Docs / TRUST & COMPLIANCE
TRUST & COMPLIANCE
Privacy & Telemetry
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex is offline-first by design. Your source code never leaves the machine. All outputs are encrypted at rest with authenticated cryptography. Telemetry is opt-in only and disabled by default.
Data Handling
Korthex supports fully air-gapped deployment (Enterprise tier). Every feature works without any internet connectivity.
| Data | Stored? | Encrypted? | Leaves Machine? |
|---|---|---|---|
| Source code | Never | - | Never |
| Finding metadata | Yes | Yes (.kxr) | Only via mesh (user-initiated) |
| Code snippets (1-2 lines per finding) | Yes | Yes (.kxr) | Never |
| Master encryption key | Yes | OS-protected (DPAPI/Keychain) | Never |
| Scan configuration | Yes | No (JSON) | Never |
| Telemetry events | Temporarily queued | No | Only if opt-in enabled |
Telemetry (Opt-In)
When you explicitly enable telemetry, Korthex collects anonymous, bucketed usage data to improve the product. The consent dialog appears on first launch. You can change your preference anytime in Settings > General > Analytics. Consent has three levels: full analytics, stability-only (crashes, unhandled errors, failed license checks and UI-freeze events only), and off. Every event type carries an internal purpose and classification tag so purpose limitation stays auditable. Data retention: raw events 90 days (then hard-dropped by partition), daily aggregates 36 months, anonymised monthly aggregates unlimited. CLI users can disable telemetry per-scan with --no-telemetry . Set the environment variable KORTHEX_NO_TELEMETRY=1 to disable globally.
| Collected (bucketed / categorical) | Never Collected |
|---|---|
| Scan duration and project size (file count) | Source code or file contents |
| Language distribution | File names or directory paths |
| Detection-rule categories triggered per scan (anonymous counts) | Exact algorithm strings from your code |
| Per-engine timing and throughput (coarse buckets) | Exact millisecond, MB, or CPU values |
| Trial funnel: started / expired / converted (days-to-conversion bucket) | Scan findings or vulnerability details |
| Feature usage (screens visited, CLI commands) | IP addresses |
| Error codes (module + exception-type bucket) | Email, license keys, or PII |
| Session ID (random UUID); install token (weekly-rotating) | Stack traces or exception messages |
Screen Protection
Korthex automatically excludes its window from screen captures and screen sharing. This prevents sensitive findings from being visible in recordings, screenshots, or screen-share sessions (Teams, Discord, Slack, Zoom, OBS, and 40+ other tools).
| Setting | Options |
|---|---|
| Privacy Mode | Default (hidden on focus loss), Strict (enhanced protection), Disabled |
| Stream Exception | Allow one app (Teams / Discord / Slack) to see Korthex during screen sharing |