# Security Statement

- Section: Imprint > Security Statement
- Canonical: https://covdbg.com/imprint/security/

---

Last updated: September 2026

## The software

### Everything happens on your machine

covdbg instruments the binary, traces it, and writes the coverage database locally. Your source code, file names, paths, and coverage data never leave your machine unless you upload a report to a service of your choice, such as Codecov.

### What does leave your machine

covdbg talks to our servers at three moments: when you sign in, when it checks whether a run is licensed, and, after a run, one small telemetry event you can switch off. The exact fields, where they come from, and how long we keep them are listed on the [Data and Telemetry](/docs/reference/data-and-telemetry/) page. All of it travels over TLS.

### Credentials on your machine

Your sign-in and the cached license decisions are stored in the Windows Credential Manager, encrypted for your Windows account, never in a file in the clear. A license decision is a token signed by our service with an Ed25519 key; covdbg verifies the signature against a key built into the binary before it believes a single field, and refuses an answer it cannot verify, however friendly it looks.

### Signed binaries

Every covdbg release is signed with our code signing certificate. Check the signature before you install.

### Build pipeline

Releases are built in isolated CI environments from tagged sources, with every dependency pinned to a known version through vcpkg. covdbg is tested under itself: the test suite runs with coverage on every build.

## The services

app.covdbg.com and telemetry.covdbg.com are operated by us. Sign-in sessions and project tokens are stored hashed. The telemetry ingest is separate from the license service, so it can be busy or down without affecting a decision. Access to production systems is limited to the people who operate them, and administrative actions are recorded in an audit trail.

We check whether a repository is public by asking its host anonymously. That probe follows no redirects, has a short timeout, and refuses addresses that resolve to private networks, so it cannot be used to reach into anybody's network.

Seats are sold through Paddle, our merchant of record. We never see or store card details.

## Reporting a vulnerability

Please report security issues privately, as described in our [responsible disclosure policy](/imprint/responsible-disclosure/). We answer within two business days and keep you informed until the issue is resolved.

## Questions

Write to [our team](/company/contact/#email-addresses).
