Trust
Nothing leaves your machine. Here is how to check.
Reports you receive are confidential by contract. So the app is built to be verifiably offline, and every claim on this page comes with a way to test it yourself.
No network by default
The free app makes no connection at all until you turn something on. There is no licence phone-home, no silent update check, no analytics, no crash upload. On first run the update check is presented unticked; you choose.
Verify it: run AsItIs under Little Snitch, LuLu or the Windows Firewall with outbound logging and open a file. You should see nothing. If you ever see a connection that is not on the list below, that is a security bug and we want the report (see disclosure, below).
Every endpoint, published
The Network activity page lists every address the app can ever contact, with what is sent and when. Today it is two items: the optional update check and the licence resend page, which opens in your browser and is never called by the app. Nothing else. The list changes only with a changelog entry that says so.
No account
There is nothing to sign up for. The free app has no login. Pro is a licence file: you buy, the licence arrives by email, you import it. We do not know when you open the app or what you open.
Offline licence files
A licence is a small file signed with Ed25519. The public key is compiled into the app; the private key is kept offline with two backups. Verification happens on your machine, in native code, with no network. A licence carries your name or firm, the seat count and an "updates until" date. Nothing in it is hidden and nothing in it is checked against a server.
How byte-clean is tested
The promise is that saving changes only the bytes you edited. It is enforced, not hoped for:
- Invariant on every save. Edits are computed as byte ranges against the original bytes. Native code splices those ranges into a copy of the original. Untouched bytes are never decoded and re-encoded, so invalid UTF-8, a lone CR, a BOM and mixed line endings survive exactly.
- Refuse on mismatch. Before the swap, the engine checks that everything outside the edited ranges is identical. If it is not, the save is refused and you are told.
- CI corpus. Every build opens and saves the benchmark corpus (6 reports with CRLF, BOM, mixed endings, no final newline, tabs, trailing spaces) plus a fuzz set of 50,000 generated files and must produce byte-identical output. A single failure blocks the release.
- Metadata matrix. Permissions, extended attributes, Finder tags, creation time and symlink targets are checked after save on macOS and on Windows (NTFS, OneDrive, network share).
- Torn-read protection. When another program (an agent, a sync client) writes the file while it is open, the watcher reads twice and compares hashes before reloading, and a save that would overwrite a newer file restores the other writer's version and shows a conflict banner.
- Network-deny test. CI runs the whole session with outbound traffic denied and fails if the app tries to connect.
A confirmed byte-integrity bug is stop-ship: fix within 24 hours where possible, and a public post-mortem.
Rendering untrusted files
A report you receive is untrusted input. HTML in markdown is sanitised, SVG and Mermaid render only as images or in sandboxed frames, javascript: and file: links are stripped from exports, and remote images are blocked until you allow them. The webview never sees a raw file path it could redirect.
Releases: signed, checksummed, with an SBOM
Mac builds are Developer ID signed and notarised. Windows builds are code signed. Each release publishes SHA-256 checksums, a CycloneDX SBOM of the app and its dependencies, and build provenance, on the GitHub release page. Updates, when you turn them on, are verified against a signing key compiled into the app before they install.
Disclosure
Report vulnerabilities privately by email to security@asitis.app (the plugin repository also accepts GitHub security reports). We acknowledge within 3 business days and share a fix timeline within 10. The machine-readable version is at /.well-known/security.txt.
In scope: any case where saving changes bytes you did not edit; sanitiser or sandbox bypasses from a crafted file; webview-to-native escalation; MCP server path traversal or writes outside the allowed root; licence or update signature bypass; any connection made without consent.
What the website collects
This site uses Plausible, a cookieless analytics service, and stores only the email you give to the waitlist. Details in the privacy policy.
Trust pack status. Endpoint list, security.txt and this page are live. Threat model page, first SBOM and a network-monitor screenshot ship with the first signed beta build. An external test comes after 1.0.