Privacy Policy & Data Guarantees
Last updated: September 2026 • Strict local execution architecture • BuonaLabs
The Zero-Telemetry Invariant
SecFirm operates strictly as a standalone desktop application on your local workstation. We do not host a cloud analysis service, and our desktop binary never transmits your APKs, decompiled source code, strings, network capture logs, or reverse engineering artifacts to any remote server.
1. Information Stored Locally on Your Machine
All workspace data, decompiled Smali, disassembled Hermes HBC bytecode, SQLite indices, and local Frida dynamic hooks reside exclusively on your local filesystem under your configured user cache directory. Deleting the project folder completely removes all analysis artifacts.
2. Information Processed by the License Server
When activating a Pro or Team commercial license, your workstation sends only:
- Your 16-character license key (e.g.
SECFIRM-PRO-XXXX-XXXX-XXXX). - A non-reversible cryptographic hardware fingerprint hash (SHA-256 derived from CPU/motherboard identifiers) solely used to bind your seat.
- Client version identifier for compatibility checking.
Enterprise offline licenses do not require or establish any outbound network connections whatsoever.
3. Customer Portal Account Data
If you create an account on our customer web portal to purchase or manage keys, we store only your email address, securely hashed password (bcrypt), and record of issued license keys. We never sell, share, or monetize account details.