radical transparency

Every byte that leaves your machine: listed here. Your code does not leave unless you send it.

Analysis is 100% local. On its own, codafort sends only two things: a pseudonymous usage metric (no code, no file path, no location of any finding) and, with an active licence, its once-a-day revalidation (the licence id and the token itself, which carries the tier, the expiry and the holder's e-mail). Code and findings leave only when you deliver them to your organisation's Platform, or connect a repository to it. It is all on this page, and telemetry you turn off in one line.

◔ Current state (honest): the mechanism exists in the binary, but the collector is not live yet: today the binary attempts the send on every interactive scan and nobody receives it. We will publish here the date collection starts. We do not claim to collect before we collect.

The red line

If a datum can identify you, your code or your target, it is not telemetry; it is yours. No telemetry carries it, on any plan: it only leaves when you deliver it to your organisation's Platform yourself (below).

✕ What telemetry NEVER carries

✕ Your code, snippets or any file content

✕ Paths, file, repository or branch names

✕ Names and versions of your dependencies

✕ Secrets, environment variables, config

✕ The location of a finding (file:line)

✕ Your IP, hostname, user or e-mail

✓ What we send (pseudonymous)

✓ That a scan happened, and how long it took (in buckets, not the exact value)

✓ How many findings, per severity

✓ Per CWE class (e.g. "SQL injection", never where)

✓ Which languages you scan

✓ codafort version, OS and architecture

✓ A random install ID, fixed, with no name or e-mail

The whole packet, exactly as it leaves

A real submission, produced by a scan that found a SQL injection. Run codafort scan . --telemetry-dry-run and see yours, byte by byte, without sending anything.

{
  "schema": "coda-telemetry/1",
  "install_id": "a3f…",            // aleatório, fixo / random, fixed
  "version": "0.1.0",
  "os": "macos", "arch": "aarch64",
  "event": "scan",
  "files_bucket": "1-9",            // faixa, nunca o nº exato / bucket, never exact
  "duration_bucket": "100ms-1s",
  "findings": {
    "by_severity":  { "critical": 1 },
    "by_cwe_class": { "89": 1 },    // classe, jamais arquivo:linha / class, never file:line
    "by_lang":      { "python": 1 }
  }
}

Levels: from total silence to your own dashboard

LevelWhat leavesDefault
0 · Silentnothing: CI, air-gap, bank/public sectorauto (CI / non-TTY)
1 · Heartbeatthe aggregate counts aboveON
2 · Productwhich rules fire, fix acceptance, false positives you markopt-in (not built yet)
3 · Your Platformnot telemetry: what you deliver to your organisation's Platform with platform push or what the connection syncs, findings with code snippets included (see below)opt-in, Platform plan

Turning it off is free and takes one line

codafort config telemetry off        # permanente / permanent
export CODAFORT_TELEMETRY=off         # sessão · CI / session · CI
codafort scan . --no-telemetry        # só desta vez / just this once
export CODAFORT_LICENSE_OFFLINE=1     # sem revalidar a licença / no licence check

When you turn the Platform on, your data leaves, and only because you sent it

The codafort platform channel is not telemetry: it delivers the analysis result to your organisation's Platform, for the queue, each finding's history and the before/after scoreboard. Nothing goes through it until you authorize this computer.

What leaves, and when

platform push: the findings (rule, severity, message and the code snippet where they are), the dependencies and the file list, with the repository name, branch and commit. The rest of the graph stays on the machine, unless you pass --with-graph. With --git, the name and e-mail of each finding's commit author go too.

Absolute paths never leave: everything goes relative to the repository root, and the send is refused if one remains.

After platform connect: one record per command in that repository, with no further send from you: the verb, the hash of the arguments, how many findings, the duration, the repository, branch and commit, the AI agent used and the fix proposals with its rationale. No paths and no code. On platform login, this machine's name becomes the device label.

How not to send it

Do not run platform login: without a session (or a token in CI), the channel has no one to talk to.

platform disconnect unlinks the repository and discards what was waiting to be sent; platform logout revokes the session.

The build for isolated environments does not have the channel. The full guide is in the documentation.

We threat-model our own telemetry

Collecting security metrics creates a target. A security company has to prove it handled that, not just promise it.

No vulnerability map

Findings leave only as counts per class, never with file, line or repository. A leak of our database cannot reconstruct "which bug, where".

No stored IP

The collector will drop the IP on arrival. No geolocation, no machine identification.

Random ID, no name

The install-id is a random number generated at install. It stays the same on that machine, which is why we treat it as pseudonymous personal data; but it carries no name, e-mail or anything about the machine.

We publish aggregates only

No number we publish singles out a customer (k-anonymity).

For isolated environments, a build with no network

The Platform contract includes a build for environments without internet access, delivered without telemetry, without online license revalidation and without the Platform channel. The network code is not in it, and an auditor can check that. The public build has all three, and telemetry turns off in one line.

And LGPD / GDPR

Level 1 is pseudonymised personal data: a fixed ID, with no name or e-mail. The legal basis is the legitimate interest in understanding and fixing the product, and you object by turning it off. On the Platform, your organisation is the controller and Orchestro processes the data as a processor, under contract and a data processing agreement, with per-customer isolation. The privacy page details each processing.