Updated September 10, 2026.
Captures and findings are saved in local project files and a SQLite index. The desktop app does not require an account or include a telemetry uploader. Operators can export data or configure remote services and extensions; those actions can transmit data to the selected destinations.
The optional update checker contacts GitHub for release metadata. Disable it with --no-update-check or NULLOCK_NO_UPDATE=1. Marketplace refreshes, feed synchronization, hosted OAST, and workspace integrations contact their configured services when used.
These static pages include no analytics or advertising scripts. Download links use the GitHub Releases API to find current assets, which sends a request from your browser to GitHub. Hosting and GitHub may process request metadata under their own policies. This project does not specify or control those providers' log-retention periods.
This site has no checkout and does not collect card details. Hosting, retention, and support policies for a paid service must be provided and agreed before that service is purchased.
Use GitHub Discussions for general questions. Keep captures, credentials, and personal information out of public posts. Vulnerability reports belong in a private security advisory.