Skip to main content

Security & data

A local-first tool with a small, well-defined online surface.

We are deliberate about what Kelavon desktop products send and store. Nothing on this page is a certification claim—it describes current product design.

Local by design

Business data lives in files and local application storage your company controls. There is no automatic upload of task records, source documents, comparison evidence or reports to our servers.

One-time activation, device-bound

The application contacts our licensing service once, at activation. Tasks may send normalized board/disk/CPU identifiers over TLS; they are used in memory and stored only as per-anchor salted hashes. Compare sends only a client-computed binding digest, so its raw hardware identifiers never leave the device. After activation verification is local, with no periodic phone-home or remote-revocation channel.

No account, no password

There is no login system. Your license is looked up by the email you purchased with, via a short-lived emailed link — see /license-help (view-only).

Payments handled by Stripe

Payments are processed by Stripe as merchant of record. Card details never touch our systems — we receive purchase status, order references and billing metadata only.

Download integrity

Download links are short-lived and cryptographically signed, never a permanent public file path. The installer itself is not currently code-signed with an Authenticode certificate, so Windows SmartScreen will report an unverified publisher on first run — verify the published SHA-256 checksum on the download page before installing.

Documented handling

Full details of how personal data is collected and used are in our Privacy Policy and License Activation Policy. Contact privacy@kelavon.com with questions.

What we do not claim

  • Device binding is intended to resist casual license sharing. It is not tamper-proof machine enforcement and cannot guarantee prevention of executable patching, local-state manipulation, complete virtual-machine cloning, disk-image duplication, or attacks performed by a person controlling the device.
  • We do not describe the software as "unhackable", "fully compliant" or "certified".
  • We do not assert regulatory compliance on your behalf — that is your organisation's assessment.
  • Claims on this page describe current behaviour and may evolve as the product matures.

Reporting a vulnerability

Email security@kelavon.com. A machine-readable /.well-known/security.txt is also published for automated tooling.