Security and privacy
What the endpoint holds, what leaves it, and what we would rather you did not have to take on trust.
What leaves your machine
Nothing, unless you configure somewhere to send it. The diagnostics tool can tell you the kind of destination — none, a local file, or a configured host — and cannot tell you the address, because the address is not in the data it reads.
What is kept, and how
What Bytesnare keeps on your machine is encrypted, with the keys held by your operating system rather than sitting next to the data. That covers the records it keeps, the queue and spool they pass through, and the threat-detection content it downloads. A machine that cannot protect data at rest keeps nothing, rather than building up a store it cannot defend.
The exception is Bytesnare’s own program files, which are ordinary files because a program has to be executable to run. They are published and signed, identical on every machine that installs Bytesnare, and contain nothing about you or your computer.
Command lines are not collected by default
And where anything is withheld by policy, Bytesnare records that it was withheld rather than presenting the result as complete.
Four channels, four sets of credentials
Telemetry, updates, control and evidence are kept apart. Telemetry only goes outward. Updates are pulled by your machine and signed. A command arriving in the wrong channel is rejected as malformed rather than obeyed — which is a property of the code, not a rule someone has to remember.
Reporting a vulnerability
Write to security@bytesnare.com. A published contact is only worth publishing once it is answered, and that mailbox is read.