Trust & security

Why you can trust it

SubnetSlinger is a tool you point at your own — and your customers' — networks. So the trust bar is high, and the answer is simple: it runs on your machine, it sends us nothing, and everything it can do is verifiable. This page is the whole story in one place; the Privacy page has the line-by-line detail.

Runs local

Your results live on your machine. We never receive them.

No telemetry

No analytics or usage tracking — ever. (A signed-in app refreshes its license on launch — on macOS, when you first open Account; nothing about your network.)

Verifiable

Code-signed per platform; the Linux download adds published checksums and a CycloneDX SBOM.

It runs on your machine

Ping, traceroute, port scan, SNMP, ARP, discovery, drift, inventory, incidents, packet captures and the Vault all run locally and are written to a folder on your computer. None of it is uploaded, sent to us, or stored on our servers. We could not show you your own scan results if you asked — we have never had them. The free tier needs no account and no internet at all.

No telemetry. No tracking.

The application collects no analytics, usage tracking, or telemetry, and runs no scan on its own. A signed-in app does refresh its license on launch — on macOS, when you first open Account — (an account call — see "What we actually collect"); if you've never signed in, no startup call is made at all. Every other network call it makes is one you triggered — and you'd find them all in a packet capture inside of a minute, which is exactly why we list them openly.

What stays, and what only leaves when you turn it on

Stays local, always

  • Every tool result
  • Vault credentials (encrypted at rest)
  • Metrics history, incidents, inventory
  • Deputy AI chats when using local Ollama
  • Anything you save or export to disk

Leaves only when you opt in

  • Cloud AI providers (your own key)
  • Account sign-in — a code to your email
  • License purchase — Stripe, in your browser
  • Internet tools you invoke (speed test, WHOIS, public IP, DNS)

Each of those runs straight from your machine to the third party and never routes through us. The full table — what each one talks to and exactly what it sends — is on the Privacy page.

Your secrets are protected

Before anything is sent to a cloud AI model— SubnetSlinger scans your message and the tool output for secret-shaped text (device passwords, SNMP/TACACS+/RADIUS keys, private keys, API tokens) and strips it out first. It's a pattern match, not an absolute guarantee: it catches well-known shapes, not everything a person could type. For something you consider truly sensitive, use the local Ollama option so nothing leaves the machine at all.

The Vault encrypts the passwords and secrets you store with AES-256-GCM under your passphrase, on your machine, and never transmits them — your passphrase is what unlocks it. How portable the encrypted file is depends on your OS: on Windows you can optionally bind it to the device for extra protection; on macOS it travels with your normal backups; on Linux it's protected by your passphrase.

A fully private AI option

The Deputy and Posse AI features are optional and off until you enable them. Choose a cloud provider and you use your own API key — the request goes from your machine to that provider, never to us, and we never see your key or your data. Or choose a local model via Ollama and the AI runs entirely on your machine with nothing leaving it. Either way the AI tools are read-only by default and don't change device configuration — the one exception is a third-party MCP server you connect and deliberately switch to "writes" (off by default).

A verifiable supply chain

Windows installs from the Microsoft Store, where Microsoft signs and hosts the package — so Smart App Control and SmartScreen trust it, and there's nothing to hand-verify.

macOS is signed with an Apple Developer ID certificate and notarized by Apple, with the notarization ticket stapled to the app — so Gatekeeper clears it on a clean Mac with no warning. Verify it yourself: spctl -a -t execute -vvv /Applications/SubnetSlinger.app, shasum -a 256 -c SubnetSlinger-1.2.0.dmg.sha256, and the detached GPG .asc with our offline key.

Linux is a direct download, so you can check it yourself. Every release is signed with a GPG key whose private half lives offline — a full compromise of our website still could not forge a signature that verifies against our public key. Ships alongside the tarball: the detached signature, SHA-256/512 checksums, the public key, and a CycloneDX Software Bill of Materials (SBOM) that's scanned for known-vulnerability (CVE) advisories — all covered by the signature.

Offline signing-key fingerprint

6285 1F0E BBD5 AA9D 6E3C  E11A 9433 D73B DB83 622C

The verify steps are on the Setup page, and the files sit next to the tarball on the Download page. Cross-check that fingerprint in more than one place — a tampered page can't match them all.

What we actually collect

For a license: your email address, a random account ID, your tier, and the fact that a payment succeeded. That's the list. No card numbers (Stripe handles the card; we're told only "paid"), no passwords (sign-in is an emailed code), no SSN, address, phone, employer, or name unless your email contains one. If our database ever leaked, it would spill a list of emails and license tiers — nothing about your network is in there to spill. Full detail on the Privacy page.

Your data is yours — you carry it

There's no cloud sync and no "restore from your account," because your account never held your data. Back up & restore (in the app) saves your work to a single file you move yourself — USB stick, file share, your own cloud drive, wherever you like. We never see it and it never touches our servers.

AISMITH PDX LLC — Oregon, USA

Questions, or something here that doesn't match what you observe? Email sheriff@subnetslinger.com or see the Privacy and Contact pages.