Compliance & Security Standards
Zero Cloud Exposure, Endpoint Security, and International Data Compliance.
1. GDPR & CCPA Compliance (Data Minimization)
Under the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), data controllers must practice strict data minimization. FlitKey achieves compliance by design:
- Zero Data Collection: FlitKey collects no personally identifiable information (PII), telemetry, IP addresses, or device identifiers.
- Full Data Portability & Right to Erasure: Users hold full physical control over their snippet database (
config.json). Deleting the local file permanently erases all stored snippets with zero residual backups on external cloud servers.
2. Local Endpoint Security & Air-Gapped Compatibility
FlitKey requires zero network sockets, zero internet connections, and zero external daemon processes. It can be safely deployed on air-gapped workstations in high-security environments, government systems, and defense networks.
3. HIPAA & Healthcare Compliance Guidance
Because FlitKey operates 100% locally on the device without transmitting data over networks, medical professionals and healthcare administrators can use FlitKey to expand medical templates and clinical notes locally. Organizations should enforce endpoint disk encryption (e.g. BitLocker or LUKS) as part of their standard HIPAA compliance policy.
4. Code Auditability & Open-Source Integrity
FlitKey's entire source code repository is public and licensed under the open-source MIT license. Security teams can independently audit the Python source code, build scripts (build_deb.py, build_windows.py), and binaries to verify that zero phone-home mechanisms exist.
5. Security Incident Reporting
If you discover a potential vulnerability or security issue, please contact our security team at security@flitkey.org or report via our Contact Form. We review security disclosures within 24 hours.