HWKeeper sees serial numbers, installed programs and the network of every computer you connect. This page explains how we protect that data and what the agent can and cannot do. Everything here describes the service as it works today; we update the page when something changes.
1. In short
- All connections — website, dashboard and agents — are encrypted (HTTPS/TLS).
- Each organization sees only its own data; the separation is enforced inside the database, not just in the application.
- Passwords are stored as bcrypt hashes; sign-in codes and links only as SHA-256 hashes.
- Each agent has its own key tied to one computer. The agent only connects out to our server; it opens no ports for incoming connections and has no remote shell.
- The agent does not collect screenshots, keystrokes, file contents, documents, emails, browser history or passwords.
- Data is stored in the European Union. Daily backups are kept for up to 14 days.
2. Encryption
- The website, the dashboard and the agent API are served over HTTPS only; plain HTTP requests are redirected to HTTPS.
- Passwords are never stored in clear text: bcrypt with 12 rounds. Email confirmation links, password reset links and sign-in codes are stored only as SHA-256 hashes and expire.
- Outgoing email is sent from our own mail server with DKIM signatures; we do not use third-party email services.
3. Isolation of each organization’s data
Every customer is a separate organization. All fleet data carries the organization’s identifier, and the database (PostgreSQL) enforces row-level security: the application works under a restricted database role, and a request can only read or change rows that belong to the organization of the signed-in user or agent. Without an organization context no rows are visible at all.
4. Accounts and access
- Roles. A viewer only looks; a manager can add and change; only an administrator can delete and manage users. Roles are checked on the server for every request.
- Registration. A new account must confirm its email address; the confirmation email contains a “this wasn’t me” link that cancels the registration.
- Sign-in protection. Attempts are rate-limited per email address and per IP address; after too many failures sign-in is paused for 15 minutes. Successful and failed sign-ins, code requests and registrations are recorded with the IP address.
- Sessions. Access tokens are valid for 15 minutes and are renewed with a refresh token valid for 30 days. Signing out removes the tokens from the browser; changing the password invalidates all previously issued tokens on every device.
- Platform administration. There is a single platform super-administrator account; it signs in only with a one-time code sent by email, cannot be created through the API or the command line, and does not belong to any customer organization.
5. The agent
- Enrollment. Each organization has its own enrollment token. When an agent registers, it receives its own key tied to that one computer; the key cannot be used for another computer or another organization.
- Outbound only. The agent connects to our API over HTTPS and opens no ports for incoming connections (for network discovery it only listens to multicast announcements on the local network). It cannot be used to control the computer remotely.
- No remote shell. The server can only ask the agent to send a snapshot now, run network discovery, apply the USB rules you configured, or update itself. Updates are downloaded from our server over HTTPS and installed only after the file’s SHA-256 checksum matches the one published by the server; an update without a checksum is refused.
- What it collects is listed in the Privacy Policy. It does not collect screenshots, keystrokes, clipboard contents, file contents, documents, emails or messages, browser history, passwords, phone numbers, contacts or text messages.
- Location and network discovery can be turned off in the agent configuration.
- Resource use. The agent is a single small program (about 10 MB) that sends a full snapshot every 15 minutes, only when something changed, and a short heartbeat every minute.
6. Infrastructure
- The service runs on a server in the European Union. The database is not reachable from the internet; only the application connects to it.
- Daily database backups are kept for up to 14 days.
- Deployments are automatic from the main branch of the source repository; every change is recorded in version control.
- Google Analytics runs on the public website only, never in the dashboard. The dashboard loads no third-party scripts.
7. What we do not do
- We do not sell data, do not use it for advertising and do not share it with advertisers.
- We do not access customer data except to provide the service, to fix a problem the customer reported, or when the law requires it.
- We do not train machine-learning models on customer data.
8. Reporting a vulnerability
If you believe you have found a security problem in HWKeeper, please write to privacy@hwkeeper.com (also listed in our security.txt). Describe what you found and how to reproduce it; we will confirm receipt and keep you informed. Please do not access other customers’ data, do not disrupt the service, and give us reasonable time to fix the problem before publishing details. We are grateful for good-faith reports and will not take legal action against researchers who follow these rules.
9. What we do not have yet
HWKeeper is a young product. We do not hold SOC 2 or ISO 27001 certifications, we have not yet commissioned an independent penetration test, and we do not run a paid bug bounty. We prefer to say this plainly rather than claim otherwise. Questions about security: privacy@hwkeeper.com.