Trust
Network activity: the complete list.
This is every address the desktop app can ever contact. If you observe anything not on this page, it is a bug. Report it and we will fix it as a security issue.
Last updated 2026-10-01. Changes to this list are announced in the changelog before they ship.
By default: nothing
Opening, reading, editing, saving, exporting to PDF or Word, importing a licence: none of these make a network connection. The app does not resolve a hostname until you opt in to the one optional feature below.
1. Update check (optional, off by default)
- Endpoint
https://updates.asitis.app/{target}/{arch}/{current_version}- When
- Only after you tick "Check for updates" on first run or in Settings. Then at most once a day while the app is open, and when you choose "Check now".
- Sent
- Your platform (
darwinorwindows), CPU architecture, and the app version you are running. Those three values are in the URL path. No identifier, no cookie, no file information. - Received
- A JSON document with the newest version, release notes and a download URL. Downloads come from the same host or from GitHub Releases, and every update is signature-checked before it installs.
- What we can learn
- An anonymous daily count of checks by version and platform. Nothing about you or your files.
- Turn off
- Settings, Updates, untick "Check for updates". The app then never contacts this host.
2. Licence resend page (a web page, not an app call)
- URL
https://asitis.app/licence/resend- When
- Only when you click "Lost your licence?" in the licence sheet. The app opens the page in your default browser; the app itself makes no request.
- Sent
- The email address you type into the page, from your browser. The page asks a Cloudflare Worker to email the licence file again; rate limited by email and IP address.
- Received
- An email with your licence file attached.
Nothing else
No licence activation call. No telemetry. No crash upload. No font or asset downloads. No "phone home" on launch. Links inside your documents open in your browser, not in the app. Remote images in a document are blocked until you allow them, and then your browser engine fetches them, which is visible in the same monitor.
How to verify
- macOS: Little Snitch or LuLu, rule "deny all" for AsItIs. Open a report, edit, save, export. No prompt should appear.
- Windows: Windows Defender Firewall with Advanced Security, outbound rule blocking
asitis.exe, audit logging on. Repeat the same steps and read the log. - Any OS: unplug the network. Everything works, including Pro.
The website (not the app)
asitis.app, the site you are reading, loads from Cloudflare Pages and, once configured, sends cookieless page views to Plausible. The waitlist form posts your email to Buttondown. None of this involves the desktop app. Details in the privacy policy.