KORTHEXDocumentation

Docs / TRUST & COMPLIANCE

TRUST & COMPLIANCE

Privacy & Telemetry

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex is offline-first by design. Your source code never leaves the machine. All outputs are encrypted at rest with authenticated cryptography. Telemetry is opt-in only and disabled by default.

Data Handling

Korthex supports fully air-gapped deployment (Enterprise tier). Every feature works without any internet connectivity.

DataStored?Encrypted?Leaves Machine?
Source codeNever-Never
Finding metadataYesYes (.kxr)Only via mesh (user-initiated)
Code snippets (1-2 lines per finding)YesYes (.kxr)Never
Master encryption keyYesOS-protected (DPAPI/Keychain)Never
Scan configurationYesNo (JSON)Never
Telemetry eventsTemporarily queuedNoOnly if opt-in enabled

Telemetry (Opt-In)

When you explicitly enable telemetry, Korthex collects anonymous, bucketed usage data to improve the product. The consent dialog appears on first launch. You can change your preference anytime in Settings > General > Analytics. Consent has three levels: full analytics, stability-only (crashes, unhandled errors, failed license checks and UI-freeze events only), and off. Every event type carries an internal purpose and classification tag so purpose limitation stays auditable. Data retention: raw events 90 days (then hard-dropped by partition), daily aggregates 36 months, anonymised monthly aggregates unlimited. CLI users can disable telemetry per-scan with --no-telemetry . Set the environment variable KORTHEX_NO_TELEMETRY=1 to disable globally.

Collected (bucketed / categorical)Never Collected
Scan duration and project size (file count)Source code or file contents
Language distributionFile names or directory paths
Detection-rule categories triggered per scan (anonymous counts)Exact algorithm strings from your code
Per-engine timing and throughput (coarse buckets)Exact millisecond, MB, or CPU values
Trial funnel: started / expired / converted (days-to-conversion bucket)Scan findings or vulnerability details
Feature usage (screens visited, CLI commands)IP addresses
Error codes (module + exception-type bucket)Email, license keys, or PII
Session ID (random UUID); install token (weekly-rotating)Stack traces or exception messages

Screen Protection

Korthex automatically excludes its window from screen captures and screen sharing. This prevents sensitive findings from being visible in recordings, screenshots, or screen-share sessions (Teams, Discord, Slack, Zoom, OBS, and 40+ other tools).

SettingOptions
Privacy ModeDefault (hidden on focus loss), Strict (enhanced protection), Disabled
Stream ExceptionAllow one app (Teams / Discord / Slack) to see Korthex during screen sharing