Security FAQ
Short answers to the questions plant security teams ask first.
Does it need internet access? No. It runs fully offline. Download and verify the image on a connected machine, then carry it in.
Can it change my firewall? No. It never connects to a firewall, Panorama or FortiAnalyzer. It writes change plans for your engineers to review and apply.
Where does my data go? Nowhere. Files are read in the browser and held in memory. See the data flow.
Can saved files be encrypted? Yes. A passphrase on Evidence setup encrypts every engagement save with AES-256-GCM in the browser, and deliverables can be exported as an AES-256 password-protected zip.
Does it collect telemetry? No telemetry, analytics, crash reporting or update checks. The app counts its own usage on your machine (seat names you type, active days, files saved by format, and engagements and firewalls as one-way hashes). Those counts are needed only to renew: you save the usage report, read it, and upload it yourself (or type its totals in, if no file may leave your network). Customers who do not renew send nothing. Configurations, rules, addresses, hostnames, client names and findings are never in it.
Is it safe on a shared jump host? Yes, bound to localhost or behind a reverse proxy with your access controls. It has no built-in sign-in by design.
How do I verify a download? Check its SHA-256 and Cosign signature. See verify a download.
Does licensing call home? No. Paid licenses are signed files checked offline, with no activation server.
Who do I tell about a vulnerability? See vulnerability disclosure.
Last updated 2026-10-02.