Our tools attach to your code while it runs. They see your memory allocations, function calls, locks and coverage data. That’s a lot of trust to ask for, so this page explains plainly what we do with your data, what we don’t do, and how we protect what we hold.
Memory Validator, Performance Validator, Coverage Validator, Thread Validator and our other tools are native Windows applications that you install and run on your own computers. All the analysis happens on your computer. The data the tools collect, such as allocation histories, call trees, coverage results and lock analysis, is saved where you choose, and none of it is sent to us.
The tools don’t collect telemetry, usage statistics or analytics. The only automatic network contact is the update check, which tells you when a new version is available. Updates are never installed silently, and older installers stay available if you need to roll back.
If one of our tools crashes, it may offer to send us a crash report. Sending it is entirely up to you: nothing goes anywhere unless you choose to send it.
If we ever add telemetry in future, it will be opt-in and disclosed in advance. It would also be limited to non-personal data, such as which tool is used, the hardware specification and the operating system version.
Every Software Verify installer is code-signed with a certificate issued by DigiCert. The private signing key is kept on dedicated hardware, and only the founder can approve a signed release. No contractor, partner or automated system has access to the signing key. Before you install, you can check the digital signature on any of our installers in Windows (right-click the file, then choose Properties → Digital Signatures).
We keep the minimum we need to sell you a licence, deliver it and support you:
| Data | Why we hold it | How it’s protected |
|---|---|---|
| Name, email address, company and postal address | Your licence, invoices and support | Kept on encrypted storage on our own premises |
| Licence name, products and expiry dates | Licence delivery and update entitlement | Kept in our web server database, hosted by Hostinger (ISO 27001 certified) and encrypted at rest |
| Order history and amounts paid | Accounting, renewals and upgrade pricing | Kept on encrypted storage on our own premises |
| Payment card details | Never held by us | Processed entirely by Stripe, a PCI-DSS Level 1 service provider |
We don’t sell or rent your data, and we never pass it to third parties for marketing.
If you use floating licences, the licence service records the logged-on username, computer name and Windows machine identifier of whoever is currently holding a seat. This is used for one thing only: showing your colleagues who has a seat, so they can ask for it to be released. It isn’t kept after the licence session ends, and it isn’t shared with anyone outside your licence pool. This is disclosed in section 10 of our licence agreement.
Sometimes the fastest way to fix a problem is for you to send us a reproduction case, a crash dump, a memory snapshot or a log file. When you do:
Software Verify is a small, founder-led company, and that limits who can reach your data. The founder holds the credentials for every critical system. Every critical account is protected by multi-factor authentication, including email, domain registration, source control, payments, hosting, banking and code signing. Each service has its own separate credentials, so a single compromised login can’t open everything.
We work with a very small number of trusted partners, one of whom has managed our web server for more than 20 years. Each partner’s access is limited to what their role needs. Access is reviewed when an engagement ends, and revoked if it’s no longer needed.
Software Verify Limited is registered in the UK, and our regulator for data protection is the Information Commissioner’s Office (ICO). We handle personal data under:
You can ask us at any time to show you the personal data we hold about you, correct it, or delete it. If we ever had a personal data breach that put your rights at risk, we would notify the ICO within 72 hours, as the law requires, and we would contact the people affected without undue delay.
We’ve been in business since February 2002. We haven’t had a breach in 24 years.
There is no customer data on the webserver worth stealing, and that’s the only DNS identifiable machine on the internet.
Any binaries that could be tampered with will lose their Software Verify digital signature which mean web browsers will produce warnings if they are downloaded.
Our tools exist to help developers find and fix bugs and improve software quality. If we know a buyer intends to use them for harm, such as exploitation, sabotage or black-hat attacks, we decline the sale and withdraw support, however much the deal is worth.
No. All analysis happens on your machines. The only automatic network contact is the check for software updates. Crash reports are sent only if you choose to send them.
Yes. Offline operation is fully supported. The tools don’t depend on any Software Verify server to run.
No. Our products are installed Windows software, sold on perpetual licences. You don’t need an online account to use them.
No, not without your explicit written consent for that specific case. Our products don’t include any AI features either.
Every installer is signed with our DigiCert code-signing certificate. Before running an installer, check that its digital signature shows Software Verify.
Yes. Send it over before you share anything sensitive.
Stripe. Your card details go straight to Stripe and never pass through our systems.
Yes. Email it to us and we’ll answer it directly.
For security, privacy or data protection questions, or to make a data request, email sales@softwareverify.com.