Security, privacy, and compliance boundaries
Use these product facts as inputs to a risk review. FlitKey is not a compliance certification.
1. Local data handling
FlitKey does not run a server that receives snippet content, typed text, IP addresses, or account identifiers. That removes one data path; it does not make a deployment compliant with GDPR, CCPA, HIPAA, or another framework.
- Zero Desktop Data Collection: The FlitKey desktop application collects no personally identifiable information (PII), telemetry, IP addresses, or device identifiers. (For marketing website metrics, see our Privacy Policy).
- Local control: Users can copy or delete
config.json. Operating-system backups, disk snapshots, or organization-managed backup tools may retain separate copies.
2. Offline and air-gapped evaluation
The application does not need a FlitKey network service to run. An organization considering an air-gapped deployment should independently review the source, build provenance, Python and PyQt dependencies, operating-system controls, update process, and installer signature. Offline operation is a technical characteristic, not approval for a high-security environment.
3. No HIPAA, GDPR, or CCPA certification
FlitKey has not been independently certified for HIPAA, GDPR, CCPA, SOC 2, ISO 27001, or a comparable standard, and it does not offer a Business Associate Agreement. Do not store protected health information, credentials, private keys, or other regulated data in snippets unless your authorized security and legal reviewers have approved the complete endpoint workflow.
4. Source code and build review
FlitKey's entire source code repository is public and licensed under the open-source MIT license. Security teams can independently audit the Python source code, build scripts (build_deb.py, build_windows.py), and binaries to verify that zero phone-home mechanisms exist.
5. Security Incident Reporting
If you discover a potential vulnerability or security issue, please contact our security team at security@flitkey.xyz or report via our Contact Form. We review security disclosures within 24 hours.