Skip to main content
Early access: get Pro free for 3 months →
DocsContact
Security & privacy

Your code never leaves your machine.

HZSec is local-first by architecture, not by toggle. The scanner runs on your CPU, against files on your disk, and writes findings to your local store. There is no upload step.

What HZSec does with your data

Source code

Stays local

The scanner reads your files directly from disk and analyzes them in-process. No copies are sent off-host. Ever.

Scan results

Stays local by default

Findings land in a local store under your home directory. You can opt into syncing them to a workspace for team review — that's an explicit, separate action.

Telemetry

Off by default

No metrics, no error pings, no usage reporting unless you opt in. We don't need it to ship a working scanner.

License keys

Validated locally

License signature checks happen offline. There is no per-scan check-in to a remote server.

Architecture guarantees

These aren't promises we can break with a config flag — they're properties of how HZSec is built.

Found a security issue in HZSec itself? We take that seriously.
Email security@hzsec.io