envman
Zero Telemetry Mandate Privacy Policy Last Updated: October 2026

Privacy Policy
Our pledge to zero network egress.

We believe developers should never have to sacrifice confidentiality for security. Here is our plain-English policy on how Envman handles data.

Summary for Engineers

Envman does not collect, store, or transmit your data. The CLI runs entirely on your local CPU and RAM. It opens zero network sockets, makes zero telemetry pings, and has no cloud server backend. Your source code, git diffs, environment files, and credentials never leave your physical workstation.

1. Zero-Egress Architecture & Zero Telemetry

The software package @fronik/envman is intentionally architected without outbound networking capabilities. When you run npx @fronik/envman init or when native Git pre-commit hooks fire, all execution takes place strictly within local node process boundaries. The software does not include telemetry trackers, Google Analytics, Sentry crash reporters, or usage metric beacons.

2. In-Memory Volatile RAM Execution

During secret validation, staged git files and AST structures are parsed directly within volatile system memory (RAM). Envman does not mirror or cache unencrypted source files to temporary disk locations (/tmp or user caches). Once the pre-commit hook exits, memory pointers are released and automatically reclaimed by the OS kernel.

3. Local Cryptographic Enclaves

When you use Envman's enclave vault features to protect .env files, encryption is performed using local hardware-accelerated AES-256-GCM. Encryption keys are bound exclusively to the local repository or developer machine. We do not provide cloud key escrow, meaning we cannot decrypt, access, or restore encrypted secrets under any circumstances.

4. Website & Documentation Browsing

This website (envman.site) is hosted on static edge infrastructure. We do not employ third-party advertising cookies, invasive tracking pixels, or user fingerprinting scripts. Server logs (such as IP addresses and requested URLs) are retained only temporarily by edge CDNs for DDoS mitigation and operational health, after which they are deleted.

5. Enterprise Air-Gapped Environments

Because Envman operates with absolute zero egress, enterprise security teams can safely install and deploy Envman within completely isolated, air-gapped development environments, financial sector intranets, and defense-grade environments without breaching SOC2, HIPAA, or ISO 27001 data residency mandates.

6. Security & Privacy Contacts

If you have questions regarding this privacy policy or would like to submit security audit findings, please open a confidential security advisory or inquiry on our official GitHub repository.