1. Zero-Egress Architecture & Zero Telemetry
The software package @fronik/envman is intentionally architected without outbound networking capabilities. When you run npx @fronik/envman init or when native Git pre-commit hooks fire, all execution takes place strictly within local node process boundaries. The software does not include telemetry trackers, Google Analytics, Sentry crash reporters, or usage metric beacons.
2. In-Memory Volatile RAM Execution
During secret validation, staged git files and AST structures are parsed directly within volatile system memory (RAM). Envman does not mirror or cache unencrypted source files to temporary disk locations (/tmp or user caches). Once the pre-commit hook exits, memory pointers are released and automatically reclaimed by the OS kernel.
3. Local Cryptographic Enclaves
When you use Envman's enclave vault features to protect .env files, encryption is performed using local hardware-accelerated AES-256-GCM. Encryption keys are bound exclusively to the local repository or developer machine. We do not provide cloud key escrow, meaning we cannot decrypt, access, or restore encrypted secrets under any circumstances.
4. Website & Documentation Browsing
This website (envman.site) is hosted on static edge infrastructure. We do not employ third-party advertising cookies, invasive tracking pixels, or user fingerprinting scripts. Server logs (such as IP addresses and requested URLs) are retained only temporarily by edge CDNs for DDoS mitigation and operational health, after which they are deleted.
5. Enterprise Air-Gapped Environments
Because Envman operates with absolute zero egress, enterprise security teams can safely install and deploy Envman within completely isolated, air-gapped development environments, financial sector intranets, and defense-grade environments without breaching SOC2, HIPAA, or ISO 27001 data residency mandates.
6. Security & Privacy Contacts
If you have questions regarding this privacy policy or would like to submit security audit findings, please open a confidential security advisory or inquiry on our official GitHub repository.