Skip to content

Security and Privacy

aiXis Studio edited this page Oct 4, 2026 · 1 revision

Security & Privacy / Sécurité & confidentialité

Full policy / politique complète : PRIVACY.md · Threat model / modèle de menace : docs/threat-model.md

🇬🇧 English

The privacy contract

  • Everything runs locally — snitch.db and logs never leave the machine. No telemetry, no analytics, no crash reporting, no account.
  • The only possible outbound call is the opt-in DB-IP Lite download in Settings — it requires an explicit click and is the single consent-gated network request in the codebase.
  • Geolocation is offline-only — DB-IP Lite ships gzip'd in backend/data/geo/ and extracts on first run. MaxMind GeoLite2-*.mmdb files dropped into <data_dir>/geo/ are also picked up.
  • LAN discovery is passive — the system ARP table, never a broadcast scan.

Authentication & exposure

Mechanism Detail
API token Per-launch random token, required on every REST endpoint and the WebSocket (X-Snitch-Token header or ?token=). Stored in data/api_token.txt.
Loopback default The API binds 127.0.0.1 in every mode. SNITCH_BIND=0.0.0.0 only if you explicitly want LAN access — token auth still applies.
Origin allowlist CORS + WebSocket origins restricted to localhost:5173, the backend's own origin, and Electron file:// pages.
No secrets in logs GET /diagnostics returns a runtime snapshot without secrets — safe to attach to bug reports.

What Snitch can see (privileges)

Live capture uses libpcap/BPF — it reads packets on your interfaces, which is why it needs elevated privileges (sudo on macOS/Linux, Npcap + admin on Windows). Snitch reads traffic; it does not modify, block or inject anything. SNITCH_DEMO=1 runs fully unprivileged.

Data retention

Sliding window in local SQLite — 24 h by default, configurable via the retention_hours setting. Aggregates live in host_history / process_history; alert suppressions in alert_suppressions. Delete the data directory to wipe everything.

🇫🇷 Français

Le contrat de confidentialité

  • Tout tourne en local — snitch.db et les logs ne quittent jamais la machine. Pas de télémétrie, pas d'analytics, pas de rapport de crash, pas de compte.
  • Le seul appel sortant possible est le téléchargement opt-in de DB-IP Lite dans Réglages — clic explicite obligatoire, c'est la seule requête réseau du code.
  • Géolocalisation 100 % hors ligne — DB-IP Lite embarquée gzipée, extraite au premier lancement. Les .mmdb MaxMind déposés dans <data_dir>/geo/ sont aussi pris en charge.
  • Découverte LAN passive — table ARP système, jamais de scan broadcast.

Authentification & exposition

Mécanisme Détail
Jeton API Jeton aléatoire par lancement, exigé sur chaque endpoint REST et le WebSocket. Stocké dans data/api_token.txt.
Loopback par défaut L'API écoute sur 127.0.0.1 dans tous les modes. SNITCH_BIND=0.0.0.0 uniquement pour un accès LAN explicite (jeton toujours exigé).
Allowlist d'origines CORS + WebSocket restreints à localhost:5173, l'origine du backend et les pages file:// d'Electron.
Aucun secret dans les logs GET /diagnostics renvoie un instantané sans secrets — sûr à joindre aux rapports de bug.

Ce que Snitch peut voir (privilèges)

La capture utilise libpcap/BPF — lecture des paquets sur vos interfaces, d'où les privilèges élevés (sudo macOS/Linux, Npcap + admin Windows). Snitch lit le trafic ; il ne modifie, ne bloque ni n'injecte rien. SNITCH_DEMO=1 fonctionne sans privilège.

Rétention des données

Fenêtre glissante en SQLite local — 24 h par défaut, configurable via retention_hours. Supprimez le dossier de données pour tout effacer.

Snitch Wiki

Getting started / Démarrage

  • Installation — EN · FR
  • Usage / Utilisation — EN · FR

Docs (EN + FR)

Help / Aide (EN + FR)

Project / Projet

Clone this wiki locally